PT-2023-6374 · Casaos · Casaos
Thomas-Chauchefoin-Sonarsource
·
Published
2023-07-17
·
Updated
2024-12-12
·
CVE-2023-37266
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CasaOS versions prior to 0.4.4
Description
Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication, allowing them to execute arbitrary commands as
root on CasaOS instances. This issue is related to weaknesses in the authentication procedure, specifically in the validation of JWTs.Recommendations
For versions prior to 0.4.4, upgrade to CasaOS 0.4.4 to resolve the issue.
If upgrading to 0.4.4 is not possible, temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly, to minimize the risk of exploitation.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Casaos