Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.
| Software | From | Fixed in |
|---|---|---|
| apache / cloudstack | 4.5.1 | 4.5.1.x |
| apache / cloudstack | 4.4.4 | 4.4.4.x |