Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1wOXhmLTc0eGgtbWh3Nc4AA0xr
1Panel command injection vulnerability in Firewall ip functionality
Summary
An OS command injection vulnerability exists in 1Panel firewall functionality. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Details
1Panel firewall functionality /hosts/firewall/ip
endpoint read user input without validation, the attacker extends the default functionality of the application, which execute system commands.
PoC
the payload ; sleep 3 #
will lead server response in 3 seconds
the payload ; sleep 6 #
will lead server response in 6 seconds
Impact
An attacker can execute arbitrary code on the target system, which can lead to a complete compromise of the system.
Patches
The vulnerability has been fixed in v1.4.3.
Workarounds
It is recommended to upgrade the version to v1.4.3.
References
If you have any questions or comments about this advisory:
Open an issue in https://github.com/1Panel-dev/1Panel
Email us at [email protected]
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wOXhmLTc0eGgtbWh3Nc4AA0xr
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 1 year ago
Updated: about 1 year ago
CVSS Score: 8.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Percentage: 0.04024
EPSS Percentile: 0.91966
Identifiers: GHSA-p9xf-74xh-mhw5, CVE-2023-37477
References:
- https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-p9xf-74xh-mhw5
- https://github.com/1Panel-dev/1Panel/commit/e17b80cff4975ee343568ff526b62319f499005d
- https://github.com/1Panel-dev/1Panel/releases/tag/v1.4.3
- https://nvd.nist.gov/vuln/detail/CVE-2023-37477
- https://github.com/advisories/GHSA-p9xf-74xh-mhw5
Blast Radius: 1.0
Affected Packages
go:github.com/1Panel-dev/1Panel
Dependent packages: 1Dependent repositories: 0
Downloads:
Affected Version Ranges: <= 1.4.2
Fixed in: 1.4.3
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.4.0, 1.4.1, 1.4.2
All unaffected versions: 1.4.3, 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.5.5, 1.6.0, 1.6.1, 1.6.2, 1.7.0, 1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.8.0, 1.8.1, 1.8.2, 1.8.3, 1.8.4, 1.8.5, 1.9.0, 1.9.1, 1.9.2, 1.9.3, 1.9.4, 1.9.5, 1.9.6