Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-34361

Опубликовано: 05 июл. 2024
Источник: nvd
CVSS3: 8.5
CVSS3: 8.8
EPSS Средний

Описание

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the gravity_DownloadBlocklistFromUrl() function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:*
Версия до 5.18.3 (исключая)

EPSS

Процентиль: 98%
0.58179
Средний

8.5 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-918

EPSS

Процентиль: 98%
0.58179
Средний

8.5 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-918