CVE-2021-31324: OS Command Injection
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31324?
CVE-2021-31324 is classified as a critical vulnerability due to its potential for remote code execution as root.
How do I fix CVE-2021-31324?
To fix CVE-2021-31324, you should update the CentOS Web Panel to the latest version where the vulnerability has been patched.
What impact does CVE-2021-31324 have on my system?
CVE-2021-31324 allows an unprivileged user to execute arbitrary commands as root, potentially compromising the entire system.
Who is affected by CVE-2021-31324?
CVE-2021-31324 affects all installations of CentOS Web Panel that include the unprivileged user portal component.
Is there a workaround for CVE-2021-31324?
While upgrading is the best solution for CVE-2021-31324, temporarily restricting user access can help mitigate risk until a patch is applied.