ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-11-30T00:00:00

Updated: 2023-11-30T22:41:40.464970

Reserved: 2023-10-23T00:00:00


Link: CVE-2023-46326

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-30T23:15:07.330

Modified: 2023-12-06T19:46:54.630


Link: CVE-2023-46326

JSON object: View

cve-icon Redhat Information

No data.

CWE