zstack records
3 published records for vendor zstack.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-613 Insufficient Session Expiration1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-32829No exploit | Post-authentication Remote Code Execution (RCE) in ZStack REST APIzstack · rest api · CWE-94 | Critical9.9 | — | 2.9% | Aug 17, 2021 |
35Monitor | CVE-2023-46326No exploit | ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of thezstack · zstack · CWE-613 | High8.8 | — | 0.7% | Nov 30, 2023 |
33Monitor | CVE-2021-32836No exploit | Pre-auth unsafe deserialization in ZStackzstack · zstack · CWE-94 | High8.1 | — | 2.0% | Sep 8, 2021 |
- CVE-2021-3282940Plan
Post-authentication Remote Code Execution (RCE) in ZStack REST API
CriticalCVSS 9.9No exploitEPSS 3%zstack · rest apiAug 17, 2021
- CVE-2023-4632635Monitor
ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of the
HighCVSS 8.8No exploitEPSS 1%zstack · zstackNov 30, 2023
- CVE-2021-3283633Monitor
Pre-auth unsafe deserialization in ZStack
HighCVSS 8.1No exploitEPSS 2%zstack · zstackSep 8, 2021