Re: [D] Comparison of Apache Cloudstack security and SEV-SNP technology. [cloudstack]

2025-04-30 Thread via GitHub
GitHub user DaanHoogland closed the discussion with a comment: Comparison of Apache Cloudstack security and SEV-SNP technology. closed this for lack of interaction, please reopen or open a new item if applicable GitHub link: https://github.com/apache/cloudstack/discussions/10141

Re: [D] Comparison of Apache Cloudstack security and SEV-SNP technology. [cloudstack]

2025-04-30 Thread via GitHub
GitHub user miloserdoff closed a discussion: Comparison of Apache Cloudstack security and SEV-SNP technology. # ISSUE TYPE * Other # COMPONENT NAME ~~~ Data Security ~~~ # CLOUDSTACK VERSION ~~~ 4.18.2.5 ~~~ # CONFIGURATION No # OS / ENVIRONMENT Ubuntu 18.04

Re: [D] Comparison of Apache Cloudstack security and SEV-SNP technology. [cloudstack]

2024-12-27 Thread via GitHub
GitHub user pcfriek1987 added a comment to the discussion: Comparison of Apache Cloudstack security and SEV-SNP technology. Not sure what kind of comparison that would be either.. as Cloudstack is software, SEV-SNP a CPU feature. GitHub link: https://github.com/apache/cloudstack

Re: [D] Comparison of Apache Cloudstack security and SEV-SNP technology. [cloudstack]

2024-12-27 Thread via GitHub
GitHub user DaanHoogland added a comment to the discussion: Comparison of Apache Cloudstack security and SEV-SNP technology. @miloserdoff , this sounds like you are asking for a document on the comparison. There is none available, so you'll have to find a volunteer to write it. GitHub

CloudStack Security Standards & Framework Adherence: ISO 27001:2022, Cloud Security Alliance – Security, Trust, Assurance, and Risk (CSA STAR)

2024-11-04 Thread Traiano Welcome
Hi I'd like to know which security standards CloudStack supports or has been made to comply with? e.g does anyone know of cloudstack being configured to comply with the following standards: ISO 27001:2022, Cloud Security Alliance – Security, Trust, Assurance, and Risk (CSA STAR) My objective is

[ADVISORY] Apache CloudStack Security Releases 4.18.1.1 and 4.19.0.1

2024-04-03 Thread Rohit Yadav
Apache CloudStack security releases 4.18.1.1 and 4.19.0.1 address the CVEs listed below. Affected users are recommended to upgrade their CloudStack installations. 1. CVE-2024-29006: x-forwarded-for HTTP header parsed by default Severity: moderate Description: By default the CloudStack

Re: [ANNOUNCE] Apache CloudStack Security Releases 4.8.1.1, 4.9.0.1

2016-10-27 Thread Rohit Yadav
is was not officially voted and I've added a note on this tag as well. The git history may be viewed to see what exactly was changed. [1] https://github.com/apache/cloudstack/releases/tag/4.5.2.2 Regards. On Thu, Oct 27, 2016 at 9:37 AM, Rohit Yadav wrote: > # Apache CloudStack Securit

[ANNOUNCE] Apache CloudStack Security Releases 4.8.1.1, 4.9.0.1

2016-10-26 Thread Rohit Yadav
# Apache CloudStack Security Releases 4.8.1.1, 4.9.0.1 The Apache CloudStack project announces security releases 4.8.1.1, 4.9.0.1 that fixes the bug causing vulnerability over previously released minor versions 4.8.1 and 4.9.0 respectively. As a security release, no new features are included but

[ANNOUNCE] Apache CloudStack Security Releases 4.5.2.1, 4.6.2.1, 4.7.1.1, 4.8.0.1

2016-06-09 Thread Rohit Yadav
# Apache CloudStack Security Releases 4.5.2.1, 4.6.2.1, 4.7.1.1, 4.8.0.1 The Apache CloudStack project announces security releases 4.5.2.1, 4.6.2.1, 4.7.1.1, 4.8.0.1 that fixes the bug causing vulnerability over previously released minor versions 4.5.2, 4.6.2, 4.7.1 and 4.8.0 respectively. As a

Re: CloudStack Security

2014-09-22 Thread Daan Hoogland
Giri, you can not have a read-only database in a functional cloud instance. CloudStack writes to the database On Mon, Sep 22, 2014 at 2:46 PM, Giri Prasad wrote: > Hi All, > Can some please inform, what are the directories, that a typical cloud > stack management server and cloud agent, writes

CloudStack Security

2014-09-22 Thread Giri Prasad
Hi All,  Can some please inform, what are the directories, that a typical cloud stack management server and cloud agent, writes into or creates files, when cloudstack is installed on a fresh linux distro.  And also, how to make the cloud database as read only, after the installation of cs and th

Apache CloudStack Security Advisory: Multiple vulnerabilities in Apache CloudStack

2013-04-24 Thread John Kinsella
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Product: Apache CloudStack Vendor: The Apache Software Foundation CVE References: CVE-2013-2756, CVE-2013-2758 Vulnerability Type(s): Authentication bypass (2756), cryptography (2758) Vulnerable version(s): Apache CloudStack version 4.0.0-incubating