Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-37477

Опубликовано: 18 июл. 2023
Источник: nvd
CVSS3: 7.2
CVSS3: 8.8
EPSS Низкий

Описание

1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall functionality. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. 1Panel firewall functionality /hosts/firewall/ip endpoint read user input without validation, the attacker extends the default functionality of the application, which execute system commands. An attacker can execute arbitrary code on the target system, which can lead to a complete compromise of the system. This issue has been addressed in commit e17b80cff49 which is included in release version 1.4.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fit2cloud:1panel:*:*:*:*:*:*:*:*
Версия до 1.4.3 (исключая)

EPSS

Процентиль: 70%
0.0063
Низкий

7.2 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-78
CWE-78

Связанные уязвимости

CVSS3: 8.8
github
больше 2 лет назад

1Panel command injection vulnerability in Firewall ip functionality

EPSS

Процентиль: 70%
0.0063
Низкий

7.2 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-78
CWE-78