HIGH

CVE-2020-11108

CVSS v3

8.8

HIGH

EPSS Score

89.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.

Technical details

Published
5/11/2020

Frequently asked questions

What is CVE-2020-11108?

The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.

Is CVE-2020-11108 actively exploited?

Active exploitation of CVE-2020-11108 has not been confirmed. The EPSS score is 89.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-11108?

CVE-2020-11108 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2020-11108 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.