CVE-2023-46326

ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zstack:zstack:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:28

Type Values Removed Values Added
References () https://github.com/zstackio/zstack/security/advisories/GHSA-w2rv-x3pp-h67q - Exploit, Vendor Advisory () https://github.com/zstackio/zstack/security/advisories/GHSA-w2rv-x3pp-h67q - Exploit, Vendor Advisory

06 Dec 2023, 19:46

Type Values Removed Values Added
References () https://github.com/zstackio/zstack/security/advisories/GHSA-w2rv-x3pp-h67q - () https://github.com/zstackio/zstack/security/advisories/GHSA-w2rv-x3pp-h67q - Exploit, Vendor Advisory
First Time Zstack
Zstack zstack
CPE cpe:2.3:a:zstack:zstack:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-613

30 Nov 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-30 23:15

Updated : 2024-11-21 08:28


NVD link : CVE-2023-46326

Mitre link : CVE-2023-46326

CVE.ORG link : CVE-2023-46326


JSON object : View

Products Affected

zstack

  • zstack
CWE
CWE-613

Insufficient Session Expiration