CVE-2014-0031: Apache Cloudstack
Medium severity, CVSS 4.0. EPSS: 2.2% chance of exploitation in the next 30 days.
The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack before 4.2.1 allow remote authenticated users to list network ACLS for other users via a crafted request.
Affected products
- Apache Cloudstack: up to and including 4.2.0; version 2.0 only; version 2.0.1 only; version 2.1.0 only; version 2.1.1 only; version 2.1.2 only; …
Published 2014-01-15. Last modified 2026-06-17.