CVE-2023-46326
PoC —CVSS 3.1
8.8 high
EPSS
<1%p52
Published
()
Modified
Description
ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.
- Vendors
- zstack
- Products
- zstack
- Weakness
- CWE-613
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.