Описание
1Panel vulnerable to command injection when entering the container terminal
Impact
The authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal.
- Vulnerability analysis.

- vulnerability reproduction.
- The successful execution of system commands.

Affected versions: <= 1.3.5
Patches
The vulnerability has been fixed in v1.3.6.
Workarounds
It is recommended to upgrade the version to v1.3.6.
References
If you have any questions or comments about this advisory:
Open an issue in https://github.com/1Panel-dev/1Panel Email us at wanghe@fit2cloud.com
Пакеты
github.com/1Panel-dev/1Panel
< 1.3.6
1.3.6
Связанные уязвимости
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal. The vulnerability has been fixed in v1.3.6.
Уязвимость панели управления Linux-сервера 1Panel, связанная с непринятием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольные команды