Vulnerabilities > CVE-2023-46326 - Insufficient Session Expiration vulnerability in Zstack
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 14 |