PT-2024-27167 · Unknown+1 · Adguardhome+1

·

CVE-2024-36814

·

Published

2024-10-08

·

Updated

2024-11-05

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Adguard Home versions prior to 0.107.52
Description An arbitrary file read issue allows authenticated attackers to access arbitrary files as root on the underlying Operating System by placing a crafted file into a readable directory. This poses a serious security risk, enabling attackers to read sensitive files on systems running Adguard Home.
Recommendations For versions prior to 0.107.52, update to version 0.107.52 or later to resolve the issue. As a temporary workaround, consider restricting access to readable directories to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-36814
GHSA-9CP9-8GW2-8V7M
GO-2024-3184
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Adguardhome
Suse