CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.
References
Link | Resource |
---|---|
https://github.com/IceWhaleTech/CasaOS/commit/d060968b7ab08e7f8cbfe7ca9ccdfa47afe9bb06 | Patch Third Party Advisory |
https://github.com/IceWhaleTech/CasaOS/issues/84 | Exploit Issue Tracking Third Party Advisory |
https://www.star123.top/2022/01/08/A-vulnerability-in-CasaOS/ | Exploit Mitigation Third Party Advisory |
https://www.star123.top/2022/01/08/A-vulnerability-in-CasaOS/#more | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-03-10 17:45
Updated : 2023-07-31 13:05
NVD link : CVE-2022-24193
Mitre link : CVE-2022-24193
CVE.ORG link : CVE-2022-24193
JSON object : View
Products Affected
icewhale
- casaos
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')