{"id":"CVE-2024-24765","aliases":["GHSA-h5gf-cmm8-cg7c","GO-2024-2616"],"url":"https://o3.security/vulnerability/CVE-2024-24765","summary":"CasaOS-UserService allows unauthorized access to any file","details":"### Summary\n\nhttp://demo.casaos.io/v1/users/image?path=/var/lib/casaos/1/avatar.png\n\nOriginally it was to get the url of the user's avatar, but the path filtering was not strict, making it possible to get any file on the system.\n\n\n### Details\n\nConstruct paths to get any file.\n\nSuch as the CasaOS user database, and furthermore can obtain system root privileges.\n\n### PoC\n\nhttp://demo.casaos.io/v1/users/image?path=/var/lib/casaos/conf/../db/user.db\n\n### Impact\n\nv0.4.6 all previous versions\n","published":"2024-03-06T17:31:56.841Z","modified":"2026-08-12T03:51:40.554770337Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/IceWhaleTech/CasaOS-UserService","fixedVersion":"0.4.7"}],"fix":{"url":"https://github.com/IceWhaleTech/CasaOS-UserService/commit/3f4558e23c0a9958f9a0e20aabc64aa8fd51840e","label":"IceWhaleTech/CasaOS-UserService@3f4558e"},"references":[{"type":"WEB","url":"https://github.com/IceWhaleTech/CasaOS-UserService/releases/tag/v0.4.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24765.json"},{"type":"ADVISORY","url":"https://github.com/IceWhaleTech/CasaOS-UserService/security/advisories/GHSA-h5gf-cmm8-cg7c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-24765"},{"type":"FIX","url":"https://github.com/IceWhaleTech/CasaOS-UserService/commit/3f4558e23c0a9958f9a0e20aabc64aa8fd51840e"},{"type":"PACKAGE","url":"https://github.com/IceWhaleTech/CasaOS-UserService"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:40.554770337Z"}}