CVE-2022-35741 is a critical XML External Entity (XXE) injection vulnerability affecting Apache CloudStack versions 4.5.0 and later, specifically within its SAML 2.0 authentication Service Provider plugin. This vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to achieve arbitrary file reading, denial of service, or server-side request forgery if the SAML 2.0 plugin is enabled. While the plugin is not enabled by default, its activation exposes the CloudStack management server to severe compromise. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.5.0, < 4.16.1.1CPE matchmatch criteria | cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:* | ||
4.17.0.0CPE matchmatch criteria | cpe:2.3:a:apache:cloudstack:4.17.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.