zstackio/zstack

zstackio/zstack

Releases17
Frequency2 months 3 weeks
Last Release
Stars1.37K
ZStack - the open-source IaaS software http://zstack.org (国内用户请至 http://zstack.io)

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH

ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.