
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-30675 is an access control flaw in Apache CloudStack affecting the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this vulnerability by specifying the domainid parameter alongside filter=self or filter=selfexecutable values to gain unauthorized visibility into templates and ISOs belonging to the ROOT domain or unrelated domains. The vulnerability affects Apache CloudStack versions 4.0.0 through 4.19.2.x and 4.20.0.0 through 4.20.0.x, and was publicly disclosed on June 11, 2025. It carries a CVSS v3.1 base score of 4.7 (Medium) (Red Hat CVE, Apache Advisory).
The root cause is improper access control (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) in the domain resolution logic of the listTemplates and listIsos API handlers. When a Domain Admin or Resource Admin supplies a domainid parameter with filter=self or filter=selfexecutable, the API incorrectly defaults domain resolution to the ROOT domain scope rather than restricting it to the caller's own domain scope. The fix enforces that domain resolution strictly adheres to the caller's scope, preventing cross-domain enumeration. Exploitation requires authenticated access with at minimum Domain Admin or Resource Admin privileges (Apache Advisory, Apache Mailing List).
A successful exploit allows a malicious admin to enumerate and extract metadata of templates and ISOs belonging to unrelated domains, violating multi-tenant isolation boundaries within Apache CloudStack. This can expose sensitive internal configuration details, template names, and ISO metadata that should be inaccessible to the attacker's domain. While the vulnerability does not allow direct code execution or data modification, the confidentiality breach could facilitate further reconnaissance or targeted attacks against other tenants (Apache Advisory, Red Hat CVE).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The vulnerability requires authenticated access with Domain Admin or Resource Admin privileges, significantly limiting the attack surface. The EPSS score is approximately 0.034% (0.000340), indicating a low probability of exploitation in the near term. CVE-2025-30675 is not listed in the CISA Known Exploited Vulnerabilities catalog (Red Hat CVE, Apache Advisory).
listTemplates or listIsos API endpoint, supplying the domainid parameter set to the ROOT domain's ID (or another target domain's ID) along with filter=self or filter=selfexecutable.listTemplates or listIsos API calls from Domain Admin or Resource Admin accounts that include both a domainid parameter referencing a domain outside the caller's own domain and filter=self or filter=selfexecutable values.listTemplates/listIsos with cross-domain domainid values from a single admin account in a short time window, suggesting enumeration activity.Apache CloudStack has released patched versions 4.19.3.0 and 4.20.1.0 that fix this vulnerability by ensuring domain resolution strictly adheres to the caller's scope. All users running versions from 4.0.0 through 4.19.2.x or 4.20.0.0 through 4.20.0.x should upgrade immediately. As interim mitigations, organizations should restrict and audit admin-level account permissions, enforce the principle of least privilege for Domain Admin and Resource Admin accounts, and monitor API logs for suspicious cross-domain listTemplates or listIsos calls (Apache Advisory, Apache Mailing List).
Security news outlets including GBHackers, CyberSecurityNews, and CyberPress covered the disclosure as part of broader reporting on the Apache CloudStack 4.19.3.0 and 4.20.1.0 security releases, which addressed multiple CVEs simultaneously. ShapeBlue, a major CloudStack contributor, published a dedicated security advisory covering the fixes in both releases (ShapeBlue Advisory). Community reaction has been measured given the Medium severity rating and the requirement for privileged access to exploit the flaw.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."