ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.
References
Link | Resource |
---|---|
https://github.com/zstackio/zstack/security/advisories/GHSA-w2rv-x3pp-h67q | Exploit Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-11-30T00:00:00
Updated: 2023-11-30T22:41:40.464970
Reserved: 2023-10-23T00:00:00
Link: CVE-2023-46326
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-11-30T23:15:07.330
Modified: 2023-12-06T19:46:54.630
Link: CVE-2023-46326
JSON object: View
Redhat Information
No data.
CWE