Record summary

CVE-2023-39965 has a selected CVSS score of 6.5 (medium).

Description

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access. Attackers can freely download the file content on the target system. This may cause a large amount of information leakage. Version 1.5.0 has a patch for this issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 4, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List= 1.4.3affected

Default status: unknown

CVE List1.4.3affected

github.com/1Panel-dev/1Panel

Browse Go / github.com/1Panel-dev/1Panel
GitHub Advisory1.4.3affected
1.4.3 to < 1.5.0 · Fixed in 1.5.0affected

References

4