Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      How To Prevent WordPress SQL Injection Attacks

      June 12, 2025

      Java never goes out of style: Celebrating 30 years of the language

      June 12, 2025

      OpenAI o3-pro available in the API, BrowserStack adds Playwright support for real iOS devices, and more – Daily News Digest

      June 12, 2025

      Creating The “Moving Highlight” Navigation Bar With JavaScript And CSS

      June 11, 2025

      Surface Pro 11 with Snapdragon X Elite drops to lowest price ever

      June 12, 2025

      With WH40K Boltgun and Dungeons of Hinterberg, this month’s Humble Choice lineup is stacked for less than $12

      June 12, 2025

      I’ve been loving the upgrade to my favorite mobile controller, and there’s even a version for large tablets

      June 12, 2025

      Copilot Vision just launched — and Microsoft already added new features

      June 12, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Master Data Management: The Key to Improved Analytics Reporting

      June 12, 2025
      Recent

      Master Data Management: The Key to Improved Analytics Reporting

      June 12, 2025

      Salesforce Lead-to-Revenue Management

      June 12, 2025

      React Native 0.80 – React 19.1, JS API Changes, Freezing Legacy Arch and much more

      June 12, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Surface Pro 11 with Snapdragon X Elite drops to lowest price ever

      June 12, 2025
      Recent

      Surface Pro 11 with Snapdragon X Elite drops to lowest price ever

      June 12, 2025

      With WH40K Boltgun and Dungeons of Hinterberg, this month’s Humble Choice lineup is stacked for less than $12

      June 12, 2025

      I’ve been loving the upgrade to my favorite mobile controller, and there’s even a version for large tablets

      June 12, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-47849 – Apache CloudStack Domain Admin Privilege Escalation Vulnerability

    CVE-2025-47849 – Apache CloudStack Domain Admin Privilege Escalation Vulnerability

    June 10, 2025

    CVE ID : CVE-2025-47849

    Published : June 10, 2025, 11:15 p.m. | 2 hours, 34 minutes ago

    Description : A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and secret key of user-accounts of Admin role type in the same domain. This operation is not appropriately restricted and allows the attacker to assume control over higher-privileged user-accounts. A malicious Domain Admin attacker can impersonate an Admin user-account and gain access to sensitive APIs and resources that could result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of infrastructure managed by CloudStack.

    Users are recommended to upgrade to Apache CloudStack 4.19.3.0 or 4.20.1.0, which fixes the issue with the following:

    * Strict validation on Role Type hierarchy: the caller’s role must be equal to or higher than the target user’s role. 
    * API privilege comparison: the caller must possess all privileges of the user they are operating on. 
    * Two new domain-level settings (restricted to the default admin): 
     - role.types.allowed.for.operations.on.accounts.of.same.role.type: Defines which role types are allowed to act on users of the same role type. Default: “Admin, DomainAdmin, ResourceAdmin”. 
     - allow.operations.on.users.in.same.account: Allows/disallows user operations within the same account. Default: true.

    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleLearn the MERN Stack in 2025
    Next Article CVE-2025-47114 – Adobe Experience Manager Stored Cross-Site Scripting Vulnerability

    Related Posts

    Security

    Apache Tomcat Under Attack: Massive Brute-Force Campaign Targets Manager Interfaces

    June 13, 2025
    Security

    Warning: Discontinued Amazon Cloud Cam Has Vulnerability (CVE-2025-6031), Exposing Your Network

    June 13, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    North Korean Konni APT Targets Ukraine with Malware to track Russian Invasion Progress

    Development

    CVE-2025-4143 – Cloudflare Workers-OAuth-Provider OAuth Redirect URI Validation Bypass

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-4991 – “3DEXPERIENCE Collaborative Industry Innovator Stored XSS”

    Common Vulnerabilities and Exposures (CVEs)

    New GPAUF Technique to Root Qualcomm-Based Android Phones

    Security

    Highlights

    Distribution Release: Wifislax 4.0

    April 4, 2025

    The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. Wifislax is a Slackware-based live disc containing a variety of security and forensics tools. The project’s latest release is Wifislax 4.0 which provides updated drivers, the latest Xfce desktop, and OpenSSL 3. “Wifislax64 version using slackware64-current base, is the development branch, so that’s where we are going to….

    Pakistan-Linked Hackers Expand Targets in India with CurlBack RAT and Spark RAT

    April 14, 2025

    159 CVEs Exploited in The Wild in Q1 2025, 8.3% of Vulnerabilities Exploited Within 1-Day

    April 25, 2025

    Elon Musk “concerned” by ChatGPT ignoring 7 shutdown commands in a row during this controlled test of OpenAI’s o3 AI model

    May 30, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.