Skip to main content

Vendor archive

icewhale CVEs

Beta · best-effort

9 CVEs tagged to vendor icewhale4 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-34171

Published Jan 2, 2026

CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug informa…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-28232

Published Apr 1, 2024

Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the l…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24766

Published Mar 6, 2024

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumer…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24767

Published Mar 6, 2024

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force a…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24765

Published Mar 6, 2024

CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making it poss…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37469

Published Aug 24, 2023

CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to successfully connect to a controlled SMB server, they are…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37266

Published Jul 17, 2023

CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary co…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-37265

Published Jul 17, 2023

CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24193

Published Mar 10, 2022

CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1