CVE-2024-2352: 1Panel swap baseApi.UpdateDeviceSwap command injection
1Panel is vulnerable to command injection. This vulnerability has been classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDeviceSwap of the file /api/v1/toolbox/device/update/swap. The manipulation of the argument Path with the input 123123123\nopen -a Calculator leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-256304.
Other sources
A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDeviceSwap of the file /api/v1/toolbox/device/update/swap. The manipulation of the argument Path with the input 123123123\nopen -a Calculator leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-256304.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2352?
CVE-2024-2352 is classified as a critical vulnerability.
How do I fix CVE-2024-2352?
To fix CVE-2024-2352, upgrade to 1Panel version 1.10.2-lts or later.
What software versions are affected by CVE-2024-2352?
CVE-2024-2352 affects 1Panel versions up to 1.10.1-lts.
What type of vulnerability is CVE-2024-2352?
CVE-2024-2352 is a command injection vulnerability.
Which specific function in 1Panel is vulnerable according to CVE-2024-2352?
The function baseApi.UpdateDeviceSwap in the file /api/v1/toolbox/device/update/swap is vulnerable.