github.com
https://github.com/1Panel-dev/1Panel CVE-2024-27288
MEDIUM
1Panel open source panel project has an unauthorized vulnerability.
Record summary
CVE-2024-27288 has a selected CVSS score of 6.3 (medium).
Description
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to the console page. The vulnerability has been fixed in v1.10.1-lts. There are no known workarounds.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 27, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 1.10.1-lts | affected | |
Default status: unknown | CVE List | Before 1.10.1-lts | affected |
github.com/1Panel-dev/1PanelBrowse Go / github.com/1Panel-dev/1Panel | GitHub Advisory | Before 1.10.1-lts · Fixed in 1.10.1-lts | affected |
References
5github.com
https://github.com/1Panel-dev/1Panel/pull/4014 github.com
https://github.com/1Panel-dev/1Panel/releases/tag/v1.10.1-lts github.comConfirmation
https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-26w3-q4j8-4xjp nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-27288