漏洞描述
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
packetstormsecurity.comhttp://packetstormsecurity.com/files/157624/Pi-hole-4.4-Remote-Code-Execution-Privilege-Escalation.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/157839/Pi-hole-4.4.0-Remote-Code-Execution.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/157748/Pi-Hole-heisenbergCompensator-Blocklist-OS-Command-Execution.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/157623/Pi-hole-4.4-Remote-Code-Execution.html↗frichetten.comhttps://frichetten.com/blog/cve-2020-11108-pihole-rce/↗