CVE-2023-37265
Summary
| CVE | CVE-2023-37265 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-17 21:15:00 UTC |
| Updated | 2023-07-31 13:05:00 UTC |
| Description | CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Icewale | Casaos | All | All | All | All |
| Operating System | Icewale | Casaos | 0.4.4 | alpha1 | All | All |
| Operating System | Icewale | Casaos | 0.4.4 | alpha2 | All | All |
| Operating System | Icewale | Casaos | 0.4.4 | alpha3 | All | All |
| Operating System | Icewale | Casaos | 0.4.4 | alpha4 | All | All |
| Operating System | Icewale | Casaos | 0.4.4 | alpha5 | All | All |
| Operating System | Icewhale | Casaos | All | All | All | All |
| Operating System | Icewhale | Casaos | 0.4.4 | alpha1 | All | All |
| Operating System | Icewhale | Casaos | 0.4.4 | alpha2 | All | All |
| Operating System | Icewhale | Casaos | 0.4.4 | alpha3 | All | All |
| Operating System | Icewhale | Casaos | 0.4.4 | alpha4 | All | All |
| Operating System | Icewhale | Casaos | 0.4.4 | alpha5 | All | All |
| Application | Icewhale | Casaos-gateway | All | All | All | All |
| Application | Icewhale | Casaos-gateway | 0.4.4 | alpha1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Incorrect identification of source IP addresses · Advisory · IceWhaleTech/CasaOS-Gateway · GitHub | MISC | github.com | |
| Merge pull request from GHSA-vjh7-5r6x-xh6g · IceWhaleTech/CasaOS-Gateway@391dd7f · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.