QID 731243
Date Published: 2024-03-14
QID 731243: Unraid Remote Code Execution (RCE) Vulnerability
UnRaid prior to version 6.81 allows remote unauthenticated attackers to execute arbitrary code.
Affected Versions:
Unraid prior to version 6.81
Patched Version:
Unraid 6.81 and later.
QID Detection Logic (Unauthenticated):
This QID sends a crafted payload to the 'webGui/images/green-on.png' endpoint as an HTTP GET request and tries to execute a PHP command. A vulnerable target will print the md5 hash of the 'qualystest731243' string.
Successful exploitation of the vulnerability may allow a remote unauthenticated attacker to execute arbitrary code remotely, leading to possible system compromise.
Solution
Customers are advised to upgrade to Unraid 6.81 or later. For more information about the vulnerabilities, please refer to the Unraid Security Advisory
Vendor References
- Unraid Security Advisory -
forums.unraid.net/topic/88253-critical-security-vulnerabilies-discovered/
CVEs related to QID 731243
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Unraid Security Advisory |
|