Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85cf-gj29-f555

Опубликовано: 10 авг. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

1Panel Arbitrary File Download vulnerability

Summary

Any file downloading vulnerability exists in 1Panel backend.

Details

Authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access. image

PoC

payload:

POST /api/v1/files/download/bypath HTTP/1.1 Host: ip Content-Type: application/json

{"path":"/etc/passwd"}

f77959349e96543436eea18283fa75c

Impact

Attackers can freely download the file content on the target system. This will be caused a large amount of information leakage.

Пакеты

Наименование

github.com/1Panel-dev/1Panel

go
Затронутые версииВерсия исправления

= 1.4.3

1.5.0

EPSS

Процентиль: 26%
0.00088
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access. Attackers can freely download the file content on the target system. This may cause a large amount of information leakage. Version 1.5.0 has a patch for this issue.

EPSS

Процентиль: 26%
0.00088
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863