PT-2024-3101 · 1Panel · 1Panel

Wanghe-Fit2Cloud

·

Published

2024-04-18

·

Updated

2025-02-11

·

CVE-2024-30257

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions 1Panel versions prior to 1.10.3-lts
Description The issue is related to the password verification in the source code of 1Panel, which uses the != symbol instead of hmac.Equal. This may lead to a timing attack vulnerability, potentially allowing an attacker to crack passwords. All users of this product are affected.
Recommendations For versions prior to 1.10.3-lts, update to version 1.10.3-lts to fix the vulnerability. As a temporary workaround, consider modifying the password verification to use hmac.Equal instead of the != symbol until a patch is applied.

Exploit

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

BDU:2024-03301
CVE-2024-30257
GHSA-6M9H-2PR2-9J8F
GO-2024-2734

Affected Products

1Panel