ZimaOS是IceWhaleTech的一个开源的操作系统项目,旨在提供一个轻量级、高性能、安全的操作系统环境。 ZimaOS 1.2.4版本之前存在访问控制错误漏洞,该漏洞源于ZimaOS中的API端点/v1/users/name允许未经身份验证的用户在未经任何授权的情况下访问敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IceWhaleTech | ZimaOS | < 1.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-49357 | 7.5 HIGH | ZimaOS (Installed Applications and System Information) has Unauthorized Sensitive Data Lea |
| CVE-2024-49359 | 7.5 HIGH | ZimaOS vulnerable to Directory Listing via Parameter Manipulation |
| CVE-2024-48931 | 7.5 HIGH | ZimaOS Arbitrary File Read via Parameter Manipulation |
| CVE-2024-49358 | 5.3 MEDIUM | ZimaOS vulnerable to Username Enumeration via API Responses |
No comments yet