In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins.
* quotaTariffCreate
* quotaTariffUpdate
* createSecondaryStorageSelector
* updateSecondaryStorageSelector
* updateHost
* updateStorage
This issue affects Apache CloudStack: from 4.18.0 before 4.20.2, from 4.21.0 before 4.22.0. Users are recommended to upgrade to versions 4.20.2 or 4.22.0, which contain the fix.
The fix introduces a new global configuration flag, js.interpretation.enabled, allowing administrators to control the interpretation of JavaScript expressions in these APIs, thereby mitigating the code injection risk.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/kwwsg2j85f1b75o0ht5zbr34d7h66788 | Vendor Advisory Mailing List |
| http://www.openwall.com/lists/oss-security/2025/11/27/2 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
02 Dec 2025, 14:36
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://lists.apache.org/thread/kwwsg2j85f1b75o0ht5zbr34d7h66788 - Vendor Advisory, Mailing List | |
| References | () http://www.openwall.com/lists/oss-security/2025/11/27/2 - Mailing List, Third Party Advisory | |
| CPE | cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:* cpe:2.3:a:apache:cloudstack:4.21.0.0:*:*:*:*:*:*:* |
|
| First Time |
Apache cloudstack
Apache |
28 Nov 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.7 |
27 Nov 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
27 Nov 2025, 12:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-27 12:15
Updated : 2025-12-02 14:36
NVD link : CVE-2025-59302
Mitre link : CVE-2025-59302
CVE.ORG link : CVE-2025-59302
JSON object : View
Products Affected
apache
- cloudstack
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
