github.com
https://github.com/1Panel-dev/1Panel CVE-2023-36457
MEDIUM
1Panel vulnerable to command injection when adding container repositories
Record summary
CVE-2023-36457 has a selected CVSS score of 6.3 (medium).
Description
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payload to achieve command injection when adding container repositories. The vulnerability has been fixed in v1.3.6.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 18, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 1.3.6 | affected | |
Default status: unknown | CVE List | Before 1.3.6 | affected |
github.com/1Panel-dev/1PanelBrowse Go / github.com/1Panel-dev/1Panel | GitHub Advisory | Before 1.3.6 · Fixed in 1.3.6 | affected |
References
4github.com
https://github.com/1Panel-dev/1Panel/releases/tag/v1.3.6 github.comConfirmation
https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-q2mx-gpjf-3h8x nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-36457