First published: Sun Mar 10 2024(Updated: )
1Panel is vulnerable to command injection. This vulnerability has been classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDeviceSwap of the file /api/v1/toolbox/device/update/swap. The manipulation of the argument Path with the input 123123123\nopen -a Calculator leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-256304.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/1Panel-dev/1Panel | <1.10.1-lts | 1.10.1-lts |
Fit2cloud 1panel | <1.10.2-lts |
https://github.com/1Panel-dev/1Panel/pull/4131/commits/0edd7a9f6f5100aab98a0ea6e5deedff7700396c
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2352 is classified as a critical vulnerability.
To fix CVE-2024-2352, upgrade to 1Panel version 1.10.2-lts or later.
CVE-2024-2352 affects 1Panel versions up to 1.10.1-lts.
CVE-2024-2352 is a command injection vulnerability.
The function baseApi.UpdateDeviceSwap in the file /api/v1/toolbox/device/update/swap is vulnerable.