github.com
https://github.com/1Panel-dev/1Panel CVE-2023-36458
MEDIUM
1Panel vulnerable to ommand injection when entering the container terminal
Record summary
CVE-2023-36458 has a selected CVSS score of 6.3 (medium).
Description
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal. The vulnerability has been fixed in v1.3.6.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 18, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | , 1.3.6 | affected | |
Default status: unknown | CVE List | Before 1.3.6 | affected |
github.com/1Panel-dev/1PanelBrowse Go / github.com/1Panel-dev/1Panel | GitHub Advisory | Before 1.3.6 · Fixed in 1.3.6 | affected |
References
4github.com
https://github.com/1Panel-dev/1Panel/releases/tag/v1.3.6 github.comConfirmation
https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-7x2c-fgx6-xf9h nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-36458