ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint http://<Zima_Server_IP:PORT>/v2_1/file
in ZimaOS is vulnerable to a directory traversal attack, allowing authenticated users to list the contents of any directory on the server. By manipulating the path parameter, attackers can access sensitive system directories such as /etc
, potentially exposing critical configuration files and increasing the risk of further attacks. As of time of publication, no known patched versions are available.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zimaos | Zimaspace | * | 1.2.5 (excluding) |
Web servers, FTP servers, and similar servers may store a set of files underneath a “root” directory that is accessible to the server’s users. Applications may store sensitive files underneath this root without also using access control to limit which users may request those files, if any. Alternately, an application might package multiple files or directories into an archive file (e.g., ZIP or tar), but the application might not exclude sensitive files that are underneath those directories. In cloud technologies and containers, this weakness might present itself in the form of misconfigured storage accounts that can be read or written by a public or anonymous user.