ZimaOS是IceWhaleTech的一个开源的操作系统项目,旨在提供一个轻量级、高性能、安全的操作系统环境。 ZimaOS 1.2.4版本之前存在信息泄露漏洞,该漏洞源于ZimaOS中的API端点会暴露已安装应用程序和系统信息等敏感数据,而无需任何身份验证或授权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IceWhaleTech | ZimaOS | <= 1.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/app_order.json` and `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/system.json`, expose sensitive data like installed applications and system information without requiring any authentication or authorization. This sensitive data leak can be exploited by attackers to gain detailed knowledge about the system setup, installed applications, and other critical information. As of time of publication, no known patched versions are available. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-49357.yaml | POC Details |
| CVE-2024-49359 | 7.5 HIGH | ZimaOS vulnerable to Directory Listing via Parameter Manipulation |
| CVE-2024-48931 | 7.5 HIGH | ZimaOS Arbitrary File Read via Parameter Manipulation |
| CVE-2024-49358 | 5.3 MEDIUM | ZimaOS vulnerable to Username Enumeration via API Responses |
| CVE-2024-48932 | 5.3 MEDIUM | ZimaOS Unauthenticated API Discloses Usernames |
No comments yet