HIGH7.5
GHSA-h5gf-cmm8-cg7c
CasaOS-UserService allows unauthorized access to any file
Quick fix
GHSA-h5gf-cmm8-cg7c — github.com/IceWhaleTech/CasaOS-UserService: upgrade to the fixed version with the command below.
go get github.com/IceWhaleTech/CasaOS-UserService@v0.4.7Details
### Summary
http://demo.casaos.io/v1/users/image?path=/var/lib/casaos/1/avatar.png
Originally it was to get the url of the user's avatar, but the path filtering was not strict, making it possible to get any file on the system.
### Details
Construct paths to get any file.
Such as the CasaOS user database, and furthermore can obtain system root privileges.
### PoC
http://demo.casaos.io/v1/users/image?path=/var/lib/casaos/conf/../db/user.db
### Impact
v0.4.6 all previous versions
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/IceWhaleTech/CasaOS-UserService
Introduced in:
0Fixed in: 0.4.7Fix
go get github.com/IceWhaleTech/CasaOS-UserService@v0.4.7References
- https://github.com/IceWhaleTech/CasaOS-UserService/security/advisories/GHSA-h5gf-cmm8-cg7c[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-24765[ADVISORY]
- https://github.com/IceWhaleTech/CasaOS-UserService/commit/3f4558e23c0a9958f9a0e20aabc64aa8fd51840e[WEB]
- https://github.com/IceWhaleTech/CasaOS-UserService[PACKAGE]
- https://github.com/IceWhaleTech/CasaOS-UserService/releases/tag/v0.4.7[WEB]