PT-2024-20546 · 1Panel · 1Panel

Wanghe-Fit2Cloud

·

Published

2024-02-05

·

Updated

2024-06-28

·

CVE-2024-24768

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions 1Panel versions prior to 1.9.6
Description The HTTPS cookie that comes with the 1Panel does not have the Secure keyword, which may cause the cookie to be sent in plain text if accessed using HTTP. This issue affects everyone who has configured the panel for HTTPS.
Recommendations For versions prior to 1.9.6, update to version 1.9.6 to resolve the issue. As a temporary workaround, consider configuring HTTPS directly for the panel to minimize the risk of exploitation. Restrict access to the panel when using HTTP to prevent the cookie from being sent in plain text.

Exploit

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-24768
GHSA-9XFW-JJQ2-7V8H
GO-2024-2531

Affected Products

1Panel