← Back to all sparks
A

Apache CloudStack

INFRA · APIS
Velocity0.0

Open-source IaaS platform for deploying and managing large virtual machine networks

Three LTS branches running in parallel, and the only release notes with substance are the CVE ones.

cloud-orchestrationlts-branchescve-advisoriestenant-isolationmaintenance-cadence
Current state
CloudStack maintains 4.19, 4.20 and 4.22 as concurrent LTS lines with 4.21 as a regular release alongside them, and ships maintenance builds across all of them on a rolling basis. Nearly every release entry is a set of pointers to release notes, install and upgrade docs with no summary of what changed. The exceptions are the security releases, which enumerate their CVEs in full.
Where it's heading
The pattern that is legible from the entries is a hardening cycle around tenant isolation. The 4.19.3.0 and 4.20.1.0 advisories covered API-key exposure and cross-domain access; a year later 4.22.0.1 covers backup access control, MinIO policy persistence after bucket deletion, resource-limit enforcement, and cross-tenant instance access through the Proxmox extension. Same class of defect, newer surfaces — the security work is tracking the platform's expansion into backup and third-party hypervisor integrations.
Prediction
Expect the paired-advisory rhythm to continue, with the next security release landing simultaneously across the supported LTS branches as 4.19.3.0/4.20.1.0 and 4.20.3.0/4.22.0.1 both did. What ships in the feature releases is not something these entries let you predict — they carry no change detail at all.

Recent moves

  1. 2mo ago

    Apache CloudStack 4.22.1.0 (LTS)

    A 4.22 maintenance build whose entry is entirely documentation links. Following six weeks after the 4.22.0.1 security release, it is the routine cleanup pass on the newest LTS line.

    View source ↗
  2. 3mo ago

    CloudStack 4.22.0.1 patches 7 CVEs across backups and templates

    Seven CVEs, five of them permission and isolation failures around backups, quota and resource limits, plus an unauthenticated command injection in direct-download templates and cross-tenant instance access via the Proxmox extension. It maps directly onto the tenant-isolation theme running through this product's advisory history.

    View source ↗
  3. 3mo ago

    Apache CloudStack 4.20.3.0 (LTS)

    Maintenance on the 4.20 LTS branch, documented only by links. Its value is keeping the older supported line current for operators who have not moved to 4.22.

    View source ↗
  4. 9mo ago

    Apache CloudStack 4.22.0.0 (LTS)

    Opens the 4.22 LTS line, the branch that subsequent security and maintenance work in this window all targets. The entry itself carries no change detail, so what distinguishes it from 4.21 is visible only in the linked release notes.

    View source ↗
  5. 9mo ago

    Apache CloudStack 4.20.2.0 (LTS)

    Another link-only 4.20 maintenance build, arriving two weeks before the 4.22 LTS line opened. Routine upkeep of a branch that remains supported in parallel.

    View source ↗
  6. 11mo ago

    Apache CloudStack 4.21.0.0 (Regular)

    The one regular, non-LTS release in the window — the track where feature work lands before being consolidated into an LTS line, which 4.22.0.0 then opened ten weeks later. As with the rest, the entry documents nothing beyond where to read about it.

    View source ↗