Record summary

CVE-2023-37266 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs in commit `705bf1f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 10, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List< 0.4.4affected

Default status: unknown

CVE ListBefore 0.4.4affected

github.com/IceWhaleTech/CasaOS

Browse Go / github.com/IceWhaleTech/CasaOS
GitHub AdvisoryBefore 0.4.4 · Fixed in 0.4.4affected

Nuclei templates

1
ProjectDiscoveryCRITICALCasaOS < 0.4.4 - Authentication Bypass via Random JWT TokenCVSS 9.8

CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs in commit `705bf1f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.

Impact

Successful exploitation allows unauthorized access to the CasaOS system.

Remediation

The problem was addressed by improving the validation of JWTs in 705bf1f. This patch is part of CasaOS 0.4.4.

WeaknessesCWE-287
Authorsiamnoooob, DhiyaneshDK, pdresearch
Template tagscve2023cveosscasaosjwticewhalevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:icewhale:casaos:*:*:*:*:*:*:*:*
Shodan: http.html:"/CasaOS-UI/public/index.html"
Shodan: http.html:"/casaos-ui/public/index.html"
FOFA: body="/CasaOS-UI/public/index.html"
FOFA: body="/casaos-ui/public/index.html"

Source: ProjectDiscovery

References

6