CVE-2023-39965
Summary
| CVE | CVE-2023-39965 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-10 18:15:00 UTC |
| Updated | 2023-09-08 16:56:00 UTC |
| Description | 1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access. Attackers can freely download the file content on the target system. This may cause a large amount of information leakage. Version 1.5.0 has a patch for this issue. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1Panel Unauthorized access in Backend · Advisory · 1Panel-dev/1Panel · GitHub | MISC | github.com | |
| Release v1.5.0 · 1Panel-dev/1Panel · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 994810 GO (Go) Security Update for github.com/1Panel-dev/1Panel (GHSA-85cf-gj29-f555)