github.com
https://github.com/pi-hole/pi-hole/commit/2c497a9a3ea099079bbcd1eb21725b0ed54b529d CVE-2024-34361
HIGH
Pi-hole Blind Server-Side Request Forgery (SSRF) vulnerability can lead to Remote Code Execution (RCE)
Record summary
CVE-2024-34361 has a selected CVSS score of 8.6 (high); EIP currently links 1 repository PoC.
Description
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_DownloadBlocklistFromUrl()` function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 8, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
pi-holeBrowse pi-hole / pi-holeDefault status: unknown | CVE List | Before 5.18.3 | affected |
| < 5.18.3 | affected |
Proofs of concept
1Repository PoCs
GitHubT0X1Cx/CVE-2024-34361-Pi-Hole-SSRF-to-RCERepository PoCby T0X1CxStars: 1Not analyzed4 files
References
2github.comConfirmation
https://github.com/pi-hole/pi-hole/security/advisories/GHSA-jg6g-rrj6-xfg6