ZimaOS是IceWhaleTech的一个开源的操作系统项目,旨在提供一个轻量级、高性能、安全的操作系统环境。 ZimaOS 1.2.4版本之前存在安全漏洞,该漏洞源于ZimaOS中的API端点/v2_1/file容易受到目录遍历攻击,允许经过身份验证的用户列出服务器上任何目录的内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IceWhaleTech | ZimaOS | <= 1.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-49357 | 7.5 HIGH | ZimaOS (Installed Applications and System Information) has Unauthorized Sensitive Data Lea |
| CVE-2024-48931 | 7.5 HIGH | ZimaOS Arbitrary File Read via Parameter Manipulation |
| CVE-2024-49358 | 5.3 MEDIUM | ZimaOS vulnerable to Username Enumeration via API Responses |
| CVE-2024-48932 | 5.3 MEDIUM | ZimaOS Unauthenticated API Discloses Usernames |
No comments yet