1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to the console page. The vulnerability has been fixed in v1.10.1-lts. There are no known workarounds.
References
| Link | Resource |
|---|---|
| https://github.com/1Panel-dev/1Panel/releases/tag/v1.10.1-lts | Release Notes |
| https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-26w3-q4j8-4xjp | Exploit Vendor Advisory |
| https://github.com/1Panel-dev/1Panel/releases/tag/v1.10.1-lts | Release Notes |
| https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-26w3-q4j8-4xjp | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-03-06 19:15
Updated : 2025-02-11 17:51
NVD link : CVE-2024-27288
Mitre link : CVE-2024-27288
CVE.ORG link : CVE-2024-27288
JSON object : View
Products Affected
fit2cloud
- 1panel
CWE
CWE-863
Incorrect Authorization
