CVE-2024-24765

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-24765
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24765.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-24765
Aliases
Related
Withdrawn
2025-02-27T03:53:47.300362Z
Published
2024-03-06T18:15:46Z
Modified
2025-02-26T19:01:53.368518Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making it possible to get any file on the system. This could allow an unauthorized actor to access, for example, the CasaOS user database, and possibly obtain system root privileges. Version 0.4.7 fixes this issue.

References

Affected packages

Git / github.com/icewhaletech/casaos-userservice

Affected ranges

Type
GIT
Repo
https://github.com/icewhaletech/casaos-userservice
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v0.*

v0.3.5-alpha1
v0.3.5-alpha2
v0.3.5-alpha3
v0.3.6
v0.3.6-alpha1
v0.3.6-alpha2
v0.3.6-alpha3
v0.3.6-alpha4
v0.3.6-alpha5
v0.3.6-alpha6
v0.3.6-alpha7
v0.3.7
v0.3.7-alpha1
v0.3.7-alpha2
v0.4.0
v0.4.0-alpha1
v0.4.0-alpha2
v0.4.0-alpha3
v0.4.0-alpha4
v0.4.0-alpha5
v0.4.0-alpha6
v0.4.1
v0.4.1-alpha1
v0.4.1-alpha2
v0.4.2
v0.4.2-alpha1
v0.4.4
v0.4.4-2-alpha1
v0.4.4-3-alpha1
v0.4.4-3-alpha2
v0.4.4-3-alpha3
v0.4.4-alpha1
v0.4.4-alpha2
v0.4.4-alpha3
v0.4.4-alpha5
v0.4.4-alpha6
v0.4.4-alpha7
v0.4.4-alpha8
v0.4.5