CVE detail
CVE-2024-34361 — CVE-2024-34361
Published 2024-07-05 · Modified 2026-06-17 · Vendor pi-hole · Product pi-hole · Source nvd
HIGH
severity
CVSS-derived band
0.0283
EPSS probability
exploitation probability, 30d
85.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_DownloadBlocklistFromUrl()` function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References