PT-2023-3483 · 1Panel · 1Panel

·

CVE-2023-36458

·

Published

2023-06-21

·

Updated

2024-08-20

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 1Panel versions prior to 1.3.6
Description The issue is related to command injection when entering the container terminal in 1Panel, an open source Linux server operation and maintenance management panel. An authenticated attacker can craft malicious payloads to achieve this. The vulnerability allows a remote attacker to execute arbitrary commands.
Recommendations For versions prior to 1.3.6, upgrade to version 1.3.6 to fix the vulnerability. As a temporary workaround, consider restricting access to the container terminal until the upgrade is applied.

Exploit

Fix

DoS

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03678
CVE-2023-36458
GHSA-7X2C-FGX6-XF9H
GO-2023-1888

Affected Products

1Panel