Sensitive Data Exposure in ZimaOS API Endpoints Affecting Zima Devices
CVE-2024-49357
What is CVE-2024-49357?
ZimaOS, a fork of CasaOS designed for Zima devices and x86-64 systems with UEFI, has exposed an alarming vulnerability in versions up to 1.2.4. The operating system’s API endpoints, such as http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/app_order.json and http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/system.json, allow for the retrieval of sensitive user and system data without any form of authentication or authorization. This significant oversight can enable malicious actors to extract crucial information about installed applications and the overall system configuration, posing severe risks to user privacy and system integrity. As of now, there are no known patched versions available, rendering systems running affected versions vulnerable to exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ZimaOS <= 1.2.4
References
CVSS V3.1
Timeline
Vulnerability published
