Vulnerabilities > CVE-2023-46326 - Insufficient Session Expiration vulnerability in Zstack

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
zstack
CWE-613

Summary

ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.

Common Weakness Enumeration (CWE)