HIGH7.5
GHSA-vc9f-mgxr-h32r
raspap-webgui vulnerable to denial of service
Quick fix
GHSA-vc9f-mgxr-h32r — billz/raspap-webgui: upgrade to the fixed version with the command below.
composer require billz/raspap-webgui:^3.1.0Details
RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to cause a persistent denial of service (bricking) via a crafted request.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/billz/raspap-webgui
Introduced in:
0Fixed in: 3.1.0Fix
composer require billz/raspap-webgui:^3.1.0References
- https://nvd.nist.gov/vuln/detail/CVE-2024-28754[ADVISORY]
- https://github.com/RaspAP/raspap-webgui/pull/1546[WEB]
- https://github.com/RaspAP/raspap-webgui/pull/1548[WEB]
- https://github.com/RaspAP/raspap-webgui/commit/d0592b63de9a5da587ab3a51e03e7e566c7f3602[WEB]
- https://dustri.org/b/carrot-disclosure.html[WEB]
- https://github.com/RaspAP/raspap-webgui[PACKAGE]