Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cloudstack | Apache | * | 4.5.1 (including) |