github.com
https://github.com/IceWhaleTech/CasaOS CVE-2022-24193
CRITICAL
Command Injection in CasaOS
Record summary
CVE-2022-24193 has a selected CVSS score of 9.8 (critical).
Description
CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
github.com/IceWhaleTech/CasaOSBrowse Go / github.com/IceWhaleTech/CasaOS | GitHub Advisory | Before 0.2.8 · Fixed in 0.2.8 | affected |
References
5github.com
https://github.com/IceWhaleTech/CasaOS/commit/d060968b7ab08e7f8cbfe7ca9ccdfa47afe9bb06 github.com
https://github.com/IceWhaleTech/CasaOS/issues/84 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-24193 star123.top
https://www.star123.top/2022/01/08/A-vulnerability-in-CasaOS