CVSS v3
8.1
HIGH
EPSS Score
1.4 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserialization vulnerability in the REST API. An attacker in control of the request body will be able to provide both the class name and the data to be deserialized and therefore will be able to instantiate an arbitrary type and assign arbitrary values to its fields. This issue may lead to a Denial Of Service. If a suitable gadget is available, then an attacker may also be able to exploit this vulnerability to gain pre-auth remote code execution. For additional details see the referenced GHSL-2021-087.
Technical details
- Published
- 2021-09-09
Frequently asked questions
What is CVE-2021-32836?
ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserialization vulnerability in the REST API. An attacker in control of the request body will be able to provide both the class name and the data to be deserialized and therefore will be able to instantiate an arbitrary type and assign arbitrary values to its fields. This issue may lead to a Denial Of Service. If a suitable gadget is available, then an attacker may also be able to exploit this vulnerability to gain pre-auth remote code execution. For additional details see the referenced GHSL-2021-087.
Is CVE-2021-32836 actively exploited?
Active exploitation of CVE-2021-32836 has not been confirmed. The EPSS score is 1.4%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2021-32836?
CVE-2021-32836 has a CVSS v3 base score of 8.1 (HIGH severity).
Is CVE-2021-32836 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2021 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).