1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to the console page. The vulnerability has been fixed in v1.10.1-lts. There are no known workarounds.
References
| Link | Resource |
|---|---|
| https://github.com/1Panel-dev/1Panel/releases/tag/v1.10.1-lts | Release Notes |
| https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-26w3-q4j8-4xjp | Exploit Vendor Advisory |
| https://github.com/1Panel-dev/1Panel/releases/tag/v1.10.1-lts | Release Notes |
| https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-26w3-q4j8-4xjp | Exploit Vendor Advisory |
Configurations
History
11 Feb 2025, 17:51
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:fit2cloud:1panel:*:*:*:*:*:*:*:* | |
| First Time |
Fit2cloud 1panel
Fit2cloud |
|
| References | () https://github.com/1Panel-dev/1Panel/releases/tag/v1.10.1-lts - Release Notes | |
| References | () https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-26w3-q4j8-4xjp - Exploit, Vendor Advisory |
21 Nov 2024, 09:04
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/1Panel-dev/1Panel/releases/tag/v1.10.1-lts - | |
| References | () https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-26w3-q4j8-4xjp - | |
| Summary |
|
06 Mar 2024, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-03-06 19:15
Updated : 2025-02-11 17:51
NVD link : CVE-2024-27288
Mitre link : CVE-2024-27288
CVE.ORG link : CVE-2024-27288
JSON object : View
Products Affected
fit2cloud
- 1panel
CWE
CWE-863
Incorrect Authorization
