PT-2023-6374 · Casaos · Casaos

Thomas-Chauchefoin-Sonarsource

·

Publicado

2023-07-17

·

Atualizado

2024-12-12

·

CVE-2023-37266

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CasaOS versions prior to 0.4.4
Description Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication, allowing them to execute arbitrary commands as root on CasaOS instances. This issue is related to weaknesses in the authentication procedure, specifically in the validation of JWTs.
Recommendations For versions prior to 0.4.4, upgrade to CasaOS 0.4.4 to resolve the issue. If upgrading to 0.4.4 is not possible, temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly, to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07086
CVE-2023-37266
GHSA-M5Q5-8MFW-P2HR
GO-2023-1931

Produtos afetados

Casaos