Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.
| Software | From | Fixed in |
|---|---|---|
| apache / cloudstack | 4.4.1 | 4.4.1.x |
| apache / cloudstack | 4.4.0 | 4.4.0.x |
| apache / cloudstack | 4.3.0 | 4.3.0.x |
| apache / cloudstack | 4.3.1 | 4.3.1.x |