PT-2021-19872 · Pi-Hole · Pi-Hole

Chris Schneider

+1

·

Published

2021-08-04

·

Updated

2022-04-25

·

CVE-2021-32706

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pi-hole versions prior to 5.5.1
Description The issue lies in the validDomainWildcard preg match filter, which allows a malicious character through that can be used to execute code, list directories, and overwrite sensitive files. This is due to one of the periods not being escaped, allowing any character to be used in its place.
Recommendations For versions prior to 5.5.1, update to version 5.5.1 to resolve the issue. As a temporary workaround, consider restricting access to the validDomainWildcard preg match filter until the patch is applied.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32706
GHSA-5CM9-6P3M-V259

Affected Products

Pi-Hole