logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-48932

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-48932

Description:
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users to access sensitive information, such as usernames, without any authorization. This vulnerability could be exploited by an attacker to enumerate usernames and leverage them for further attacks, such as brute-force or phishing campaigns. As of time of publication, no known patched versions are available.
Last updated date:
11/06/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
11/06/2024
Reference url to background

https://github.com/IceWhaleTech/ZimaOS/security/advisories/GHSA-9mrr-px2c-w42c

Type:
exploit
Confidence:
HIGH
Date of publishing:
11/06/2024
Reference url to background

https://youtu.be/wJFq8cuyFm4

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy