PT-2023-3483 · 1Panel · 1Panel

Wanghe-Fit2Cloud

·

Publicado

2023-06-21

·

Atualizado

2024-08-20

·

CVE-2023-36458

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 1Panel versions prior to 1.3.6
Description The issue is related to command injection when entering the container terminal in 1Panel, an open source Linux server operation and maintenance management panel. An authenticated attacker can craft malicious payloads to achieve this. The vulnerability allows a remote attacker to execute arbitrary commands.
Recommendations For versions prior to 1.3.6, upgrade to version 1.3.6 to fix the vulnerability. As a temporary workaround, consider restricting access to the container terminal until the upgrade is applied.

Exploit

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03678
CVE-2023-36458
GHSA-7X2C-FGX6-XF9H
GO-2023-1888

Produtos afetados

1Panel