Page 5 of 40 results (0.004 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

KubePi is an opensource kubernetes management panel. The endpoint /kubepi/api/v1/users/search?pageNum=1&&pageSize=10 leak password hash of any user (including admin). A sufficiently motivated attacker may be able to crack leaded password hashes. This issue has been addressed in version 1.6.5. • https://github.com/1Panel-dev/KubePi/security/advisories/GHSA-87f6-8gr7-pc6h • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 1

KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can become admin by editing the `isadmin` value in the request. As a result any user may take administrative control of KubePi. This issue has been addressed in version 1.6.5. Users are advised to upgrade. • https://github.com/1Panel-dev/KubePi/security/advisories/GHSA-757p-vx43-fp9r • CWE-269: Improper Privilege Management •

CVSS: 8.8EPSS: 2%CPEs: 1EXPL: 1

1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall functionality. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. 1Panel firewall functionality `/hosts/firewall/ip` endpoint read user input without validation, the attacker extends the default functionality of the application, which execute system commands. An attacker can execute arbitrary code on the target system, which can lead to a complete compromise of the system. • https://github.com/1Panel-dev/1Panel/commit/e17b80cff4975ee343568ff526b62319f499005d https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-p9xf-74xh-mhw5 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payload to achieve command injection when adding container repositories. The vulnerability has been fixed in v1.3.6. • https://github.com/1Panel-dev/1Panel/releases/tag/v1.3.6 https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-q2mx-gpjf-3h8x • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal. The vulnerability has been fixed in v1.3.6. • https://github.com/1Panel-dev/1Panel/releases/tag/v1.3.6 https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-7x2c-fgx6-xf9h • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •