Vulnerability Description
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users to access sensitive information, such as usernames, without any authorization. This vulnerability could be exploited by an attacker to enumerate usernames and leverage them for further attacks, such as brute-force or phishing campaigns. As of time of publication, no known patched versions are available.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zimaspace | Zimaos | < 1.2.5 |
Related Weaknesses (CWE)
References
- https://github.com/IceWhaleTech/ZimaOS/security/advisories/GHSA-57r9-43pc-gcp2
- https://github.com/IceWhaleTech/ZimaOS/security/advisories/GHSA-9mrr-px2c-w42cExploitVendor Advisory
- https://youtu.be/wJFq8cuyFm4Exploit
FAQ
What is CVE-2024-48932?
CVE-2024-48932 is a vulnerability with a CVSS score of 5.3 (MEDIUM). ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users...
How severe is CVE-2024-48932?
CVE-2024-48932 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-48932?
Check the references section above for vendor advisories and patch information. Affected products include: Zimaspace Zimaos.