Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

x/vulndb: potential Go vuln in github.com/1Panel-dev/1Panel: CVE-2024-2352 #2674

Closed
GoVulnBot opened this issue Apr 3, 2024 · 1 comment

Comments

@GoVulnBot
Copy link

CVE-2024-2352 references github.com/1Panel-dev/1Panel, which may be a Go module.

Description:
A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDeviceSwap of the file /api/v1/toolbox/device/update/swap. The manipulation of the argument Path with the input 123123123\nopen -a Calculator leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-256304.

References:

Cross references:

See doc/triage.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/1Panel-dev/1Panel
      vulnerable_at: 1.9.6
      packages:
        - package: 1Panel
cves:
    - CVE-2024-2352
references:
    - web: https://vuldb.com/?id.256304
    - web: https://vuldb.com/?ctiid.256304
    - fix: https://github.com/1Panel-dev/1Panel/pull/4131
    - fix: https://github.com/1Panel-dev/1Panel/pull/4131#issue-2176105990
    - fix: https://github.com/1Panel-dev/1Panel/pull/4131/commits/0edd7a9f6f5100aab98a0ea6e5deedff7700396c

@tatianab
Copy link
Contributor

tatianab commented Apr 3, 2024

Duplicate of #2636

@tatianab tatianab marked this as a duplicate of #2636 Apr 3, 2024
@tatianab tatianab closed this as completed Apr 3, 2024
# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

2 participants