QID 376490

Date Published: 2022-03-30

QID 376490: Pi-Hole Web Interface Remote Code Execution (RCE) Vulnerability

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application which acts as a DNS sinkhole and optionally a DHCP server, intended for use on a private network.

Affected Versions:
Pi-hole Web (aka AdminLTE) prior to v4.3.2
QID Detection Logic(Authenticated)
It checks for the vulnerable version for Pihole using command pihole -v -c

Successful exploitation will lead to Remote Code Execution

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers can refer to following for further updates Pi-hole Security Update.
    Vendor References

    CVEs related to QID 376490

    Software Advisories
    Advisory ID Software Component Link
    Pi-Hole Web Version URL Logo github.com/pi-hole/AdminLTE/releases/tag/v4.3.3