Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/IceWhaleTech/CasaOS-Gateway: CVE-2023-37265 #1934

Closed
GoVulnBot opened this issue Jul 17, 2023 · 1 comment

Comments

@GoVulnBot
Copy link

CVE-2023-37265 references github.com/IceWhaleTech/CasaOS-Gateway, which may be a Go module.

Description:
CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as root on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in 391dd7f. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.

References:

Cross references:
No existing reports found with this module or alias.

See doc/triage.md for instructions on how to triage this report.

modules:
    - module: github.com/IceWhaleTech/CasaOS-Gateway
      vulnerable_at: 0.4.4
      packages:
        - package: CasaOS-Gateway
description: |-
    CasaOS is an open-source Personal Cloud system. Due to a lack of IP address
    verification an unauthenticated attackers can execute arbitrary commands as
    `root` on CasaOS instances. The problem was addressed by improving the detection
    of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users
    should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict
    access to CasaOS to untrusted users, for instance by not exposing it publicly.
cves:
    - CVE-2023-37265
references:
    - advisory: https://github.com/IceWhaleTech/CasaOS-Gateway/security/advisories/GHSA-vjh7-5r6x-xh6g
    - fix: https://github.com/IceWhaleTech/CasaOS-Gateway/commit/391dd7f0f239020c46bf057cfa25f82031fc15f7

@neild
Copy link
Contributor

neild commented Jul 25, 2023

Duplicate of #1932

@neild neild marked this as a duplicate of #1932 Jul 25, 2023
@neild neild closed this as completed Jul 25, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants