Record summary

CVE-2024-34361 has a selected CVSS score of 8.6 (high); EIP currently links 1 repository PoC.

Description

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_DownloadBlocklistFromUrl()` function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 8, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListBefore 5.18.3affected
< 5.18.3affected

Proofs of concept

1

Repository PoCs

GitHubT0X1Cx/CVE-2024-34361-Pi-Hole-SSRF-to-RCERepository PoCby T0X1CxStars: 1Not analyzed4 files

1.2 MiB

GitHub

PoC details

References

2