PT-2024-19921 · 1Panel · 1Panel

Linyz-Tel

·

Published

2024-03-09

·

Updated

2024-06-04

·

CVE-2024-2352

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 1Panel versions up to 1.10.1-lts
Description A critical issue has been found in the function baseApi.UpdateDeviceSwap of the file /api/v1/toolbox/device/update/swap. The manipulation of the argument Path with a specific input leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations To fix this issue, apply a patch to the affected version of 1Panel. As a temporary workaround, consider restricting access to the /api/v1/toolbox/device/update/swap endpoint until a patch is available. Avoid using the Path argument in the affected API endpoint until the issue is resolved.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2352
GHSA-X2VG-5WRF-VJ6V
GO-2024-2636

Affected Products

1Panel