VDB
Sign up
MEDIUM4.3

GHSA-mwwc-3jv2-62j3

AdGuardHome vulnerable to Cross-Site Request Forgery

Quick fix

GHSA-mwwc-3jv2-62j3 — github.com/AdguardTeam/AdGuardHome: upgrade to the fixed version with the command below.

go get github.com/AdguardTeam/AdGuardHome@v0.108.0-b.16

Details

In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering rules.

The file that contains the vulnerable code is no longer present as of v0.108.0-b.16.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/AdguardTeam/AdGuardHome
Introduced in: 0.95Fixed in: 0.108.0-b.16
Fixgo get github.com/AdguardTeam/AdGuardHome@v0.108.0-b.16

References