PT-2024-27167 · Unknown+1 · Adguardhome+1

Itz-D0Dgy

+1

·

Published

2024-10-08

·

Updated

2024-11-05

·

CVE-2024-36814

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Adguard Home versions prior to 0.107.52
Description An arbitrary file read issue allows authenticated attackers to access arbitrary files as root on the underlying Operating System by placing a crafted file into a readable directory. This poses a serious security risk, enabling attackers to read sensitive files on systems running Adguard Home.
Recommendations For versions prior to 0.107.52, update to version 0.107.52 or later to resolve the issue. As a temporary workaround, consider restricting access to readable directories to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-36814
GHSA-9CP9-8GW2-8V7M
GO-2024-3184
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Adguardhome
Suse