—
GO-2023-2026
CasaOS Command Injection vulnerability in github.com/IceWhaleTech/CasaOS
Quick fix
GO-2023-2026 — github.com/IceWhaleTech/CasaOS: upgrade to the fixed version with the command below.
go get github.com/IceWhaleTech/CasaOS@v0.4.4Details
CasaOS Command Injection vulnerability in github.com/IceWhaleTech/CasaOS
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/IceWhaleTech/CasaOS
Introduced in:
0Fixed in: 0.4.4Fix
go get github.com/IceWhaleTech/CasaOS@v0.4.4References
- https://github.com/advisories/GHSA-92vc-4fcw-g68q[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-37469[ADVISORY]
- https://securitylab.github.com/advisories/GHSL-2022-119_CasaOS[ADVISORY]
- https://github.com/IceWhaleTech/CasaOS/commit/af440eac5563644854ff33f72041e52d3fd1f47c[FIX]
- https://github.com/IceWhaleTech/CasaOS/blob/96e92842357230098c771bc41fd3baf46189b859/route/v1/samba.go#L121[WEB]
- https://github.com/IceWhaleTech/CasaOS/blob/96e92842357230098c771bc41fd3baf46189b859/service/connections.go#L58[WEB]
- https://github.com/IceWhaleTech/CasaOS/releases/tag/v0.4.4[WEB]