CVE-2025-34171
Last modified
CVE-2025-34171 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug information. The /v1/users/image endpoint can be abused with a user-controlled path parameter to access files under /var/lib/casaos/1/, which reveals installed applications and configuration details. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug information. The /v1/users/image endpoint can be abused with a user-controlled path parameter to access files under /var/lib/casaos/1/, which reveals installed applications and configuration details. Additionally, /v1/sys/debug discloses host operating system, kernel, hardware, and storage information. The endpoints also return distinct error messages, enabling file existence enumeration of arbitrary paths on the underlying host filesystem. This information disclosure can be used for reconnaissance and to facilitate targeted follow-up attacks against services deployed on the host.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Icewhale | Casaos | <= 0.4.15 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-34171?
How severe is CVE-2025-34171?
How do I fix CVE-2025-34171?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-34166Rejected reason: This CVE ID was rejected because it was res…
- CVE-2025-34167Rejected reason: This CVE ID was rejected because it was res…
- CVE-2025-34168Rejected reason: This CVE ID was rejected because it was res…
- CVE-2025-34169Rejected reason: This CVE ID was rejected because it was res…
- CVE-2025-3417The Embedder plugin for WordPress is vulnerable to unauthori…8.8
- CVE-2025-34170Rejected reason: This CVE ID was rejected because it was res…
- CVE-2025-34172In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the …6.1
- CVE-2025-34173In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, …4.3
- CVE-2025-34174In pfSense CE /usr/local/www/status_traffic_totals.php, the …5.4
- CVE-2025-34175In pfSense CE /usr/local/www/suricata/suricata_filecheck.php…6.1
- CVE-2025-34176In pfSense CE /suricata/suricata_ip_reputation.php, the valu…4.3
- CVE-2025-34177In pfSense CE /suricata/suricata_flow_stream.php, the value …5.4
Are you affected by CVE-2025-34171?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
