CVE-2024-24765

HIGH

CasaOS-UserService <0.4.7 - Path Traversal

Title source: llm
STIX 2.1

Description

CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making it possible to get any file on the system. This could allow an unauthorized actor to access, for example, the CasaOS user database, and possibly obtain system root privileges. Version 0.4.7 fixes this issue.

Scores

CVSS v3 7.5
EPSS 0.0046
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-200
Status published
Products (2)
icewhale/casaos < 0.4.7
IceWhaleTech/CasaOS-UserService 0 - 0.4.7Go
Published Mar 06, 2024
Tracked Since Feb 18, 2026