CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making it possible to get any file on the system. This could allow an unauthorized actor to access, for example, the CasaOS user database, and possibly obtain system root privileges. Version 0.4.7 fixes this issue.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-03-06T17:31:56.841Z
Updated: 2024-08-06T14:01:47.283Z
Reserved: 2024-01-29T20:51:26.011Z
Link: CVE-2024-24765
Vulnrichment
Updated: 2024-08-01T23:28:12.928Z
NVD
Status : Awaiting Analysis
Published: 2024-03-06T18:15:46.807
Modified: 2024-11-21T08:59:39.437
Link: CVE-2024-24765
Redhat
No data.