Medium
CVSS 5.0
Overview
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attack...
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: