PT-2023-3483 · 1Panel · 1Panel

Wanghe-Fit2Cloud

·

Published

2023-06-21

·

Updated

2024-08-20

·

CVE-2023-36458

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 1Panel versions prior to 1.3.6
Description The issue is related to command injection when entering the container terminal in 1Panel, an open source Linux server operation and maintenance management panel. An authenticated attacker can craft malicious payloads to achieve this. The vulnerability allows a remote attacker to execute arbitrary commands.
Recommendations For versions prior to 1.3.6, upgrade to version 1.3.6 to fix the vulnerability. As a temporary workaround, consider restricting access to the container terminal until the upgrade is applied.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-03678
CVE-2023-36458
GHSA-7X2C-FGX6-XF9H
GO-2023-1888

Affected Products

1Panel