PT-2017-17560 · Deluge+2 · Deluge+2

Jonatan Nyberg

·

Published

2017-03-18

·

Updated

2020-07-08

·

CVE-2017-7178

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Deluge versions prior to 1.3.14
Description A CSRF issue was found in the web UI of Deluge. The exploitation involves hosting a crafted plugin that executes an arbitrary program from its init .py file and causing the victim to download, install, and enable this plugin.
Recommendations For Deluge versions prior to 1.3.14, update to version 1.3.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin installation feature to minimize the risk of exploitation. Avoid installing plugins from untrusted sources until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2355
CVE-2017-7178
DLA-863-1
DSA-3856-1
OPENSUSE-SU-2017_1497-1

Affected Products

Alt Linux
Deluge
Suse