ZeroHour

CVE-2023-46326

PoC
CVSS 3.1
8.8 high
EPSS
<1%p52
Published
()
Modified
Description

ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.

Vendors
zstack
Products
zstack
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.