Zstackio Zstack vulnerabilities
2 known vulnerabilities affecting zstackio/zstack.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2021-32829P2CRITICALCVSS 9.9fixed in 3.8.21v>=3.10.0, < 3.10.8+1 more2021-08-17
CVE-2021-32829 [CRITICAL] CWE-94 CVE-2021-32829: ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, man
ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networking all by APIs. Affected versions of ZStack REST API are vulnerable to post-authentication Remote Code Execution (RCE) via bypass of the Groovy shell sandbox. The REST API exposes the GET zstack/v1/bat
nvd
CVE-2021-32836P3HIGHCVSS 8.1fixed in 3.10.12v>= 4.0.0, < 4.1.62021-09-09
CVE-2021-32836 [HIGH] CWE-94 CVE-2021-32836: ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12
ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserialization vulnerability in the REST API. An attacker in control of the request body will be able to provide both the class name and the data to be deserialized and therefore will be able to instantiate an arbitra
nvd