CVE-2024-49357
ZimaOS (Installed Applications and System Information) has Unauthorized Sensitive Data Leak
Record summary
CVE-2024-49357 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/app_order.json` and `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/system.json`, expose sensitive data like installed applications and system information without requiring any authentication or authorization. This sensitive data leak can be exploited by attackers to gain detailed knowledge about the system setup, installed applications, and other critical information. As of time of publication, no known patched versions are available.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 25, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | <= 1.2.4 | affected |
| Through 1.2.4 | affected |
Nuclei templates
1ProjectDiscoveryHIGHZimaOS <= v1.2.4 - Sensitive Information DisclosureCVSS 7.5
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/app_order.json` and `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/system.json`, expose sensitive data like installed applications and system information without requiring any authentication or authorization. This sensitive data leak can be exploited by attackers to gain detailed knowledge about the system setup, installed applications, and other critical information. As of time of publication, no known patched versions are available.
Impact
Attackers can access sensitive system and application data, potentially aiding further malicious activities or reconnaissance.
Remediation
Upgrade ZimaOS to v1.2.5 or later.
Source: ProjectDiscovery