Showing 3 vulnerabilities on this page for github.com/IceWhaleTech/CasaOS

Signals CISA KEV Ransomware Nuclei
Go vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

CasaOS Command Injection vulnerability

CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to successfully connect to a controlled SMB server, they are able to execute arbitrary commands. Version 0.4.4 contains a patch for the issue.

CWE-77Aug 24, 2023
CVSS-v4.0EPSS1.27%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Weak json web token (JWT) secrets in CasaOS

CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs in commit `705bf1f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly

CWE-1391CWE-287Jul 17, 20231 related artifact
CVSS9.8v3.1EPSS6.79%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Command Injection in CasaOS

CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.

CWE-78Mar 7, 2022
CVSS9.8v3.1EPSS5.61%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX