Sploitus

CVE-2024-34361

4 known exploits for CVE-2024-34361

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_DownloadBlocklistFromUrl()` function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.

Affected products
Pi-Hole
Pi-hole
< 5.18.3
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
2.8% (86th percentile)
Weakness
CWE-918
NVD status
Analyzed
Published
2024-07-05
CVE-2024-34361 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2024-34361

Proof-of-concept code and exploit modules indexed by Sploitus