Описание
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the gravity_DownloadBlocklistFromUrl() function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.
Ссылки
- Patch
- ExploitVendor Advisory
- Patch
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.18.3 (исключая)
cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.58179
Средний
8.5 High
CVSS3
8.8 High
CVSS3
Дефекты
CWE-918
EPSS
Процентиль: 98%
0.58179
Средний
8.5 High
CVSS3
8.8 High
CVSS3
Дефекты
CWE-918