PT-2024-25809 · 1Panel · 1Panel

An5Er

·

Published

2024-05-09

·

Updated

2025-02-07

·

CVE-2024-34352

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions 1Panel versions prior to 1.10.3-lts
Description The issue is related to command injections in the project that are not well filtered, leading to arbitrary file writes and ultimately to remote code executions (RCEs). The mirror configuration write symbol > can be used to achieve arbitrary file writing. This can be exploited by sending a maliciously crafted packet to write to an arbitrary file, potentially leading to a host takeover. The vulnerability can be exploited through the "/api/v1/containers/search/log" API endpoint, allowing an attacker to write customized files, such as ssh keys, and execute any command.
Recommendations For versions prior to 1.10.3-lts, update to version 1.10.3-lts to fix the vulnerability. As a temporary workaround, consider restricting access to the "/api/v1/containers/search/log" API endpoint to minimize the risk of exploitation. Additionally, avoid using the mirror configuration write symbol > until the issue is resolved.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-34352
GHSA-F8CH-W75V-C847
GO-2024-2830

Affected Products

1Panel