Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9xfw-jjq2-7v8h

Опубликовано: 05 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 3.5

Описание

1Panel set-cookie is missing the Secure keyword

Summary

The https cookie that comes with the panel does not have the Secure keyword, which may cause the cookie to be sent in plain text when accessing http accidentally.

https://developer.mozilla.org/zh-CN/docs/Web/HTTP/Headers/Set-Cookie#secure

PoC

Directly configure https for the panel, and then capture the packet when logging in again and find that the cookie does not have the Secure keyword

Impact

Everyone who has configured the panel https

Пакеты

Наименование

github.com/1Panel-dev/1Panel

go
Затронутые версииВерсия исправления

<= 1.9.5

1.9.6

EPSS

Процентиль: 15%
0.00048
Низкий

3.5 Low

CVSS3

Дефекты

CWE-311
CWE-315

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure keyword, which may cause the cookie to be sent in plain text if accessed using HTTP. This issue has been patched in version 1.9.6.

EPSS

Процентиль: 15%
0.00048
Низкий

3.5 Low

CVSS3

Дефекты

CWE-311
CWE-315