Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Releases: apache/cloudstack

Apache CloudStack 4.22.0.0 (LTS)

11 Nov 14:25

Choose a tag to compare

Apache CloudStack 4.20.2.0 (LTS)

27 Oct 08:34
4.20.2.0
4dc3931

Choose a tag to compare

Apache CloudStack 4.21.0.0 (Regular)

29 Aug 04:57
f9513b4

Choose a tag to compare

Apache CloudStack 4.20.1.0 (LTS)

10 Jun 14:51

Choose a tag to compare

Apache CloudStack 4.20 maintenance release

Release notes: https://docs.cloudstack.apache.org/en/4.20.1.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.20.1.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.20.1.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.20.1.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.20

This LTS release includes fixes for the following security issues:

  • CVE-2025-26521: CKS cluster in project exposes user API keys
  • CVE-2025-30675: Unauthorised template/ISO list access to the domain/resource admins
  • CVE-2025-47713: Domain Admin can reset Admin password in Root Domain
  • CVE-2025-47849: Insecure access of user's API/Secret Keys in the same domain
  • CVE-2025-22829: Unauthorised access to dedicated resources in Quota plugin

Advisory: https://cloudstack.apache.org/blog/cve-advisories-4.19.3.0-4.20.1.0

Apache CloudStack 4.19.3.0 (LTS)

10 Jun 14:50

Choose a tag to compare

Apache CloudStack 4.19 maintenance release

Release notes: https://docs.cloudstack.apache.org/en/4.19.3.0/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.19.3.0/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.19.3.0/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.19.3.0/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.19

This LTS release includes fixes for the following security issues:

  • CVE-2025-26521: CKS cluster in project exposes user API keys
  • CVE-2025-30675: Unauthorised template/ISO list access to the domain/resource admins
  • CVE-2025-47713: Domain Admin can reset Admin password in Root Domain
  • CVE-2025-47849: Insecure access of user's API/Secret Keys in the same domain

Advisory: https://cloudstack.apache.org/blog/cve-advisories-4.19.3.0-4.20.1.0

Apache CloudStack 4.19.2.0 (LTS)

03 Mar 11:01

Choose a tag to compare

Apache CloudStack 4.20.0.0 (LTS)

02 Dec 13:42

Choose a tag to compare

Apache CloudStack 4.19.1.3 (LTS Security Release)

12 Nov 13:46
4.19.1.3

Choose a tag to compare

Apache CloudStack 4.18.2.5 (Security Release)

12 Nov 13:40
4.18.2.5

Choose a tag to compare

Apache CloudStack 4.19.1.2 (LTS Security Release)

15 Oct 18:35

Choose a tag to compare

This is a security release that fixes the following on top of the 4.19.1.1 release:

  • CVE-2024-45219: Uploaded and registered templates and volumes can be used to abuse KVM-based infrastructure
  • CVE-2024-45461: Access checks not enforced in Quota
  • CVE-2024-45462: Incomplete session invalidation on web interface logout
  • CVE-2024-45693: Request origin validation bypass makes account takeover possible

Advisory: https://cloudstack.apache.org/blog/security-release-advisory-4.18.2.4-4.19.1.2

Release notes: https://docs.cloudstack.apache.org/en/4.19.1.2/releasenotes
Installation docs: https://docs.cloudstack.apache.org/en/4.19.1.2/installguide
Upgrade docs: https://docs.cloudstack.apache.org/en/4.19.1.2/upgrading
Admin docs: https://docs.cloudstack.apache.org/en/4.19.1.2/adminguide
API docs: https://cloudstack.apache.org/api/apidocs-4.19

Morty Proxy This is a proxified and sanitized view of the page, visit original site.