Vulnerability Description
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pi-Hole | Pi-Hole | <= 4.4 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/157623/Pi-hole-4.4-Remote-Code-Execution.htExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157624/Pi-hole-4.4-Remote-Code-Execution-PrExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157748/Pi-Hole-heisenbergCompensator-Blockl
- http://packetstormsecurity.com/files/157839/Pi-hole-4.4.0-Remote-Code-Execution.
- https://frichetten.com/blog/cve-2020-11108-pihole-rce/ExploitThird Party Advisory
- https://github.com/Frichetten/CVE-2020-11108-PoCExploitThird Party Advisory
- http://packetstormsecurity.com/files/157623/Pi-hole-4.4-Remote-Code-Execution.htExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157624/Pi-hole-4.4-Remote-Code-Execution-PrExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157748/Pi-Hole-heisenbergCompensator-Blockl
- http://packetstormsecurity.com/files/157839/Pi-hole-4.4.0-Remote-Code-Execution.
- https://frichetten.com/blog/cve-2020-11108-pihole-rce/ExploitThird Party Advisory
- https://github.com/Frichetten/CVE-2020-11108-PoCExploitThird Party Advisory
FAQ
What is CVE-2020-11108?
CVE-2020-11108 is a vulnerability with a CVSS score of 8.8 (HIGH). The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Als...
How severe is CVE-2020-11108?
CVE-2020-11108 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11108?
Check the references section above for vendor advisories and patch information. Affected products include: Pi-Hole Pi-Hole.