ZimaOS是IceWhaleTech的一个开源的操作系统项目,旨在提供一个轻量级、高性能、安全的操作系统环境。 ZimaOS 1.2.4版本之前存在安全漏洞,该漏洞源于ZimaOS中的API端点/v1/users/login根据用户名是否存在或密码是否正确返回不同的响应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IceWhaleTech | ZimaOS | <= 1.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-49357 | 7.5 HIGH | ZimaOS (Installed Applications and System Information) has Unauthorized Sensitive Data Lea |
| CVE-2024-49359 | 7.5 HIGH | ZimaOS vulnerable to Directory Listing via Parameter Manipulation |
| CVE-2024-48931 | 7.5 HIGH | ZimaOS Arbitrary File Read via Parameter Manipulation |
| CVE-2024-48932 | 5.3 MEDIUM | ZimaOS Unauthenticated API Discloses Usernames |
No comments yet