CVE Feed

    Dashboard / CVE / CVE-2024-24765

    CVE-2024-24765

    CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making it possible to get any file on the system. This could allow an unauthorized actor to access, for example, the CasaOS user database, and possibly obtain system root privileges. Version 0.4.7 fixes this issue.

    Published:Mar 6, 2024
    Last Modified:Feb 26, 2025
    EPS:Mar 6, 2024
    EPSS Score:0.00461
    CVSS Score:7.5

    Affected Products

    Vendor
    Icewhale
    Product
    Casaos

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High