CVE-2024-44069

Source
https://cve.org/CVERecord?id=CVE-2024-44069
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-44069.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-44069
Published
2024-08-19T00:00:00Z
Modified
2026-07-15T01:49:17.543010030Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value (Celsius, Fahrenheit, or Kelvin), seen by the device owner, is unclear.

Database specific
{
    "isDisputed": true,
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/44xxx/CVE-2024-44069.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/pi-hole/pi-hole

Affected ranges

Type
GIT
Repo
https://github.com/pi-hole/pi-hole
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.0"
        }
    ],
    "cpe": "cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:*"
}
Type
GIT
Repo
https://github.com/pi-hole/web
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "DESCRIPTION",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6"
        }
    ]
}

Affected versions

0.*
0.1
1.*
1.0
1.1
1.2
1.2.1
2.*
2.0
2.0.0
2.1.0
2.1.1
2.8
V2.*
V2.5.1
V2.9.1
V2.9.2
v1.*
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.7
v1.2
v1.3
v1.4
v1.4.1
v1.4.2
v1.4.3
v1.4.3.1
v1.4.3.1a
v1.4.4
v1.4.4.1
v1.4.4.2
v2.*
v2.0
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.5
v2.1
v2.1.0-alpha-1
v2.1.0-beta
v2.1.2
v2.10
v2.10.1
v2.10.2
v2.11
v2.11.1
v2.11.2
v2.12
v2.12.1
v2.13
v2.13.1
v2.13.2
v2.2
v2.2.0
v2.3
v2.3.1
v2.4
v2.5
v2.5.1
v2.5.2
v2.5.3
v2.6
v2.6.1
v2.6.1.1
v2.6.1.2
v2.6.2
v2.6.3
v2.7
v2.7.1
v2.8.1
v2.9
v2.9.3
v2.9.4
v2.9.4a
v2.9.5
v3.*
v3.0
v3.0.1
v3.0.1a
v3.1
v3.1.4
v3.2
v3.2.1
v3.3
v3.3.1
v4.*
v4.0
v4.1
v4.1.1
v4.2
v4.2.1
v4.2.2
v4.3
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4
v5.*
v5.0
v5.1
v5.1.1
v5.1.2
v5.10
v5.10.1
v5.11
v5.11.1
v5.11.2
v5.11.3
v5.11.4
v5.12
v5.12.1
v5.12.2
v5.13
v5.14
v5.14.1
v5.14.2
v5.15
v5.15.1
v5.15.2
v5.15.3
v5.15.4
v5.15.5
v5.16
v5.16.1
v5.16.2
v5.17
v5.17.1
v5.17.2
v5.17.3
v5.18
v5.18.1
v5.18.2
v5.18.3
v5.18.4
v5.19
v5.2
v5.2.1
v5.2.2
v5.2.3
v5.2.4
v5.20
v5.20.1
v5.20.2
v5.21
v5.3
v5.3.1
v5.3.2
v5.4
v5.5
v5.5.1
v5.6
v5.7
v5.8
v5.8.1
v5.9
v5.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-44069.json"