Pi-hole vulnerability allows remote command execution
CVE-2024-34361
8.6HIGH
Key Information:
Badges
👾 Exploit Exists🟣 EPSS 52%
What is CVE-2024-34361?
A vulnerability exists in Pi-hole versions prior to 5.18.3 that allows an authenticated user to make internal requests to the server via the gravity_DownloadBlocklistFromUrl() function. Exploitation of this vulnerability may lead to unauthorized remote command execution, posing a significant security risk for users. The issue is rectified in version 5.18.3. Users are strongly advised to update their systems to enhance security.
Affected Version(s)
pi-hole < 5.18.3
References
EPSS Score
52% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published