Reporting Potential Vulnerabilities in Apache CloudStack

If you've found an issue that you believe is a security vulnerability in a released version of CloudStack, please report it to security@apache.org with details about the vulnerability, how it might be exploited, and any additional information that might be useful.

Upon notification, the ACS security team will initiate the security response procedure. If the issue is validated, the team generally takes 2-4 weeks from notification to public announcement of the vulnerability. During this time, the team will communicate with you as they proceed through the response procedure, and ask that the issue not be announced before an agreed-upon date.

The security team asks that you please do not create publicly-viewable JIRA tickets related to the issue. If validated, a JIRA ticket with the security flag set will be created for tracking the issue in a non-public manner.

Security Team

The PMC has decided to create a "Security Team" for CloudStack.  To read more about team membership and activities, please visit CloudStack Security Team

Scope of ACS Vulnerability Responses

The scope of these procedures applies to vulnerabilities found in CloudStack releases 4.0.0-incubating and later. 

CloudStack has an history that pre-dates the Apache Software Foundation.  This includes the 2.0.x, 2.1.x, 2.2.x, and 3.0.x series of CloudStack releases. Vulnerabilities that are present in only these releases will be addressed by Citrix.

Some vulnerabilities may exist in ASF code releases as well as derivative works or binary distributions.  This is discussed in the Distributors section below.

Procedure for Responding to Potential Security Issues

Distributor Coordination

The CloudStack Security Team will coordinate with members of the Security pre-disclosure list to receive early warning about security issues before they are disclosed to the general public.