CVE-2021-45466: Critical severity centos web panel vulnerability
Published Dec 26, 2022
·Updated
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=addserver&DHCP= to add an authorizedkeys text file in the /resources/ folder.
Affected Software
1 affected component
Control-webpanel Webpanel<0.9.8.1107
Event History
Dec 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45466?
CVE-2021-45466 is classified as a high severity vulnerability.
2
How can CVE-2021-45466 be exploited?
CVE-2021-45466 can be exploited by attackers sending crafted requests to the API to add unauthorized keys.
3
What versions of CWP are affected by CVE-2021-45466?
CVE-2021-45466 affects CWP versions before 0.9.8.1107.
4
How do I fix CVE-2021-45466?
To fix CVE-2021-45466, update CWP to version 0.9.8.1107 or later.
5
What files are targeted in CVE-2021-45466?
In CVE-2021-45466, attackers can add an authorized_keys file in the /resources/ directory.