CVE-2021-29448

Source
https://cve.org/CVERecord?id=CVE-2021-29448
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29448.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-29448
Aliases
  • GHSA-cwwf-93p7-73j9
Published
2021-04-15T16:15:14.033Z
Modified
2026-08-07T17:28:04.389856Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H CVSS Calculator
Summary
[none]
Details

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.

References

Affected packages

Git / github.com/pi-hole/ftl

Affected ranges

Type
GIT
Repo
https://github.com/pi-hole/ftl
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:pi-hole:ftldns:5.7:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "5.7"
        },
        {
            "last_affected": "5.7"
        }
    ]
}

Affected versions

5.*
5.7
v5.*
v5.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29448.json"

Git / github.com/pi-hole/pi-hole

Affected ranges

Type
GIT
Repo
https://github.com/pi-hole/pi-hole
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:pi-hole:pi-hole:5.2.4:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "5.2.4"
        },
        {
            "last_affected": "5.2.4"
        }
    ]
}

Affected versions

5.*
5.2.4
v5.*
v5.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29448.json"

Git / github.com/pi-hole/web

Affected ranges

Type
GIT
Repo
https://github.com/pi-hole/web
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:pi-hole:web_interface:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.5"
        }
    ]
}

Affected versions

0.*
0.1
1.*
1.0
1.1
1.2
1.2.1
2.*
2.0.0
2.1.0
2.1.1
v1.*
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.7
v1.2
v1.3
v1.4
v1.4.1
v1.4.2
v1.4.3
v1.4.3.1
v1.4.3.1a
v1.4.4
v1.4.4.1
v1.4.4.2
v2.*
v2.0
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.5
v2.1
v2.1.0-alpha-1
v2.1.0-beta
v2.1.2
v2.2
v2.2.0
v2.3
v2.3.1
v2.4
v2.5
v2.5.1
v2.5.2
v3.*
v3.0
v3.0.1
v3.0.1a
v3.1
v3.2
v3.2.1
v3.3
v4.*
v4.0
v4.1
v4.1.1
v4.2
v4.3
v4.3.2
v4.3.3
v5.*
v5.0
v5.1
v5.1.1
v5.2
v5.2.1
v5.2.2
v5.3
v5.3.1
v5.3.2
v5.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29448.json"