1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to the console page. The vulnerability has been fixed in v1.10.1-lts. There are no known workarounds.
References
Link | Resource |
---|---|
https://github.com/1Panel-dev/1Panel/releases/tag/v1.10.1-lts | Release Notes |
https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-26w3-q4j8-4xjp | Exploit Vendor Advisory |
https://github.com/1Panel-dev/1Panel/releases/tag/v1.10.1-lts | Release Notes |
https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-26w3-q4j8-4xjp | Exploit Vendor Advisory |
Configurations
History
11 Feb 2025, 17:51
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:fit2cloud:1panel:*:*:*:*:*:*:*:* | |
First Time |
Fit2cloud 1panel
Fit2cloud |
|
References | () https://github.com/1Panel-dev/1Panel/releases/tag/v1.10.1-lts - Release Notes | |
References | () https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-26w3-q4j8-4xjp - Exploit, Vendor Advisory |
21 Nov 2024, 09:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/1Panel-dev/1Panel/releases/tag/v1.10.1-lts - | |
References | () https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-26w3-q4j8-4xjp - | |
Summary |
|
06 Mar 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-06 19:15
Updated : 2025-02-11 17:51
NVD link : CVE-2024-27288
Mitre link : CVE-2024-27288
CVE.ORG link : CVE-2024-27288
JSON object : View
Products Affected
fit2cloud
- 1panel
CWE
CWE-863
Incorrect Authorization