Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.
| Software | From | Fixed in |
|---|---|---|
| apache / cloudstack | 4.4.1 | 4.4.1.x |
| apache / cloudstack | - | 4.3.1.x |
| apache / cloudstack | 4.4.0 | 4.4.0.x |