Логотип exploitDog
bind:CVE-2024-24765
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-24765

Количество 2

Количество 2

nvd логотип

CVE-2024-24765

почти 2 года назад

CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making it possible to get any file on the system. This could allow an unauthorized actor to access, for example, the CasaOS user database, and possibly obtain system root privileges. Version 0.4.7 fixes this issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h5gf-cmm8-cg7c

почти 2 года назад

CasaOS-UserService allows unauthorized access to any file

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-24765

CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making it possible to get any file on the system. This could allow an unauthorized actor to access, for example, the CasaOS user database, and possibly obtain system root privileges. Version 0.4.7 fixes this issue.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-h5gf-cmm8-cg7c

CasaOS-UserService allows unauthorized access to any file

CVSS3: 7.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу