Описание
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.
A flaw was found in Plesk. An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives. This can result in arbitrary file write as root, leading to full privilege escalation on the underlying server.
Отчет
Critical:An improper authorization vulnerability exists in the Plesk XML API that allows an authenticated user to inject arbitrary configuration directives, potentially resulting in arbitrary file writes as root and privilege escalation. Although the go-acme/lego dependency is present, Red Hat OpenShift Dev Spaces does not ship or use the affected Plesk functionality. Therefore, the vulnerable code path is not exposed in this product.
Меры по смягчению последствий
Red Hat OpenShift Dev Spaces is not affected because it does not ship or rely on Plesk or expose the Plesk XML API. The vulnerable functionality resides within the Plesk-specific integration of the go-acme/lego library, which is not used by the product. Authentication is also required to exploit the vulnerability. No product changes are required.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/traefik-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
9.9 Critical
CVSS3
Связанные уязвимости
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.
EPSS
9.9 Critical
CVSS3