CVE-2024-34361 | pi-hole up to 5.18.2 gravity_DownloadBlocklistFromUrl server-side request forgery (GHSA-jg6g-rrj6-xfg6)
A vulnerability, which was classified as critical, has been found in pi-hole up to 5.18.2. The affected element is the function gravity_DownloadBlocklistFromUrl. This manipulation causes server-side request forgery.
This vulnerability is tracked as CVE-2024-34361. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.