PT-2024-20546 · 1Panel · 1Panel
Wanghe-Fit2Cloud
·
Published
2024-02-05
·
Updated
2024-06-28
·
CVE-2024-24768
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
1Panel versions prior to 1.9.6
Description
The HTTPS cookie that comes with the 1Panel does not have the Secure keyword, which may cause the cookie to be sent in plain text if accessed using HTTP. This issue affects everyone who has configured the panel for HTTPS.
Recommendations
For versions prior to 1.9.6, update to version 1.9.6 to resolve the issue. As a temporary workaround, consider configuring HTTPS directly for the panel to minimize the risk of exploitation. Restrict access to the panel when using HTTP to prevent the cookie from being sent in plain text.
Exploit
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
1Panel