GHSA-m5q5-8mfw-p2hr

    Dashboard / Vulnerabilities / GHSA-m5q5-8mfw-p2hr

    GHSA-m5q5-8mfw-p2hr

    Published: 17 Jul 2023Last Modified: 12 Dec 2024

    Summary: CasaOS contains weak JWT secrets

    Details: ### Impact Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. ### Patches The problem was addressed by improving the validation of JWTs in 705bf1f. This patch is part of CasaOS 0.4.4. ### Workarounds Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly. ### References - 705bf1f - https://www.sonarsource.com/blog/security-vulnerabilities-in-casaos/

    Affected packages

    Package

    Name: github.com/IceWhaleTech/CasaOS

    Purl: pkg:golang/github.com/IceWhaleTech/CasaOS

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.4.4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-m5q5-8mfw-p2hr | CVE-DB