2023-12-01 00:57:12 +00:00
{
"id" : "CVE-2023-46326" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2023-11-30T23:15:07.330" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T08:28:18.467" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-12-01 00:57:12 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation."
2023-12-06 21:00:22 +00:00
} ,
{
"lang" : "es" ,
"value" : "ZStack Cloud versi\u00f3n 3.10.38 y anteriores permite el acceso API no autenticado a la lista de UUID de trabajos activos y al ID de sesi\u00f3n para cada uno de ellos. Esto conduce a una escalada de privilegios."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH" ,
2023-12-06 21:00:22 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-12-06 21:00:22 +00:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-613"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zstack:zstack:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "3.10.38" ,
"matchCriteriaId" : "ECBBB9BF-7859-4003-A194-88990835C074"
}
]
}
]
2023-12-01 00:57:12 +00:00
}
] ,
"references" : [
{
"url" : "https://github.com/zstackio/zstack/security/advisories/GHSA-w2rv-x3pp-h67q" ,
2023-12-06 21:00:22 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit" ,
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://github.com/zstackio/zstack/security/advisories/GHSA-w2rv-x3pp-h67q" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Vendor Advisory"
]
2023-12-01 00:57:12 +00:00
}
]
}