PT-2026-99384 · Froxlor · Froxlor
CVSS v3.1
7.8
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Froxlor versions prior to 2.3.12
Description
A time-of-check time-of-use (TOCTOU) race condition exists in the SSH key synchronization cron within the
SshKeys::generateFiles() function located in lib/Froxlor/Cron/System/SshKeys.php. TOCTOU is a software bug where a program checks the state of a resource before using it, but the state changes between the check and the use. The validation performed by FileDir::makeCorrectDir() and makeCorrectFile() occurs only at check time, while the filesystem path is re-resolved as root during the write process. On installations where the system.allow customer shell variable is set to 1, granting customers local shell access, an attacker can replace their ~/.ssh directory with a symlink after the check but before the write. This allows the root-run cron to append the customer's public key to /root/.ssh/authorized keys and change the ownership of /root/.ssh to the customer, leading to full root compromise of the panel host.Recommendations
Update to version 2.3.12.
As a temporary mitigation, set the
system.allow customer shell variable to 0 to restrict local shell access for customers.Exploit
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Froxlor