CVE Explorer
CVE-2025-69233
Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domains. This can be used by an attacker to degrade the infrastructure's resources and lead to denial of service conditions.
Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-770","description":"CWE-770 Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:63e9aa5ecb93a017d18d71622f2e3bac2f8f3ec3814cbdacba1e1a5b3ef1f34c · sha256:dfeda245422b8ccf… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-367","description":"CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:63e9aa5ecb93a017d18d71622f2e3bac2f8f3ec3814cbdacba1e1a5b3ef1f34c · sha256:dfeda245422b8ccf… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Apache CloudStack","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"4.20.2.0","status":"affected","version":"4.0.0","versionType":"semver"},{"lessThanOrEqual":"4.22.0.0","status":"affected","version":"4.21.0.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:63e9aa5ecb93a017d18d71622f2e3bac2f8f3ec3814cbdacba1e1a5b3ef1f34c · sha256:dfeda245422b8ccf… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:63e9aa5ecb93a017d18d71622f2e3bac2f8f3ec3814cbdacba1e1a5b3ef1f34c · sha256:dfeda245422b8ccf… · /containers/cna/metrics/1/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-770","description":"CWE-770 Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:63e9aa5ecb93a017d18d71622f2e3bac2f8f3ec3814cbdacba1e1a5b3ef1f34c · sha256:dfeda245422b8ccf… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-367","description":"CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:63e9aa5ecb93a017d18d71622f2e3bac2f8f3ec3814cbdacba1e1a5b3ef1f34c · sha256:dfeda245422b8ccf… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/05/09/5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:63e9aa5ecb93a017d18d71622f2e3bac2f8f3ec3814cbdacba1e1a5b3ef1f34c · sha256:dfeda245422b8ccf… · /containers/adp/1/references/0
{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/n8mt5b7wkpysstb8w7rr9f02kc5cq2xm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:63e9aa5ecb93a017d18d71622f2e3bac2f8f3ec3814cbdacba1e1a5b3ef1f34c · sha256:dfeda245422b8ccf… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.