GHSA-vjh7-5r6x-xh6g

    Dashboard / Vulnerabilities / GHSA-vjh7-5r6x-xh6g

    GHSA-vjh7-5r6x-xh6g

    Published: 17 Jul 2023Last Modified: 10 Sept 2026

    Summary: CasaOS Gateway vulnerable to incorrect identification of source IP addresses

    Details: ### Impact Unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. ### Patches The problem was addressed by improving the detection of client IP addresses in 391dd7f. This patch is part of CasaOS 0.4.4. ### Workarounds Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly. ### References - 391dd7f - https://www.sonarsource.com/blog/security-vulnerabilities-in-casaos/

    Affected packages

    Package

    Name: github.com/IceWhaleTech/CasaOS-Gateway

    Purl: pkg:golang/github.com/IceWhaleTech/CasaOS-Gateway

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.4.4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-vjh7-5r6x-xh6g | CVE-DB