CasaOS Command Injection vulnerability
CVE-2023-37469
8.8HIGH
What is CVE-2023-37469?
CasaOS, an open-source personal cloud system developed by IceWhaleTech, has a vulnerability that allows authenticated users to execute arbitrary commands when connected to a controlled SMB server. This issue affects all versions prior to 0.4.4, which includes a security patch to remediate the flaw. Users are urged to update their installations to the latest version to ensure protection against this exploit. For more detailed information on this vulnerability, visit the advisories and commits provided.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CasaOS < 0.4.4
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
