Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-4C35946F93393FEDCAC9E7799CCE262E
HistoryAug 10, 2023 - 12:00 a.m.

Incorrect Authorization

2023-08-1000:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
6
linux
server management
unauthorized access

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

24.0%

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access. Attackers can freely download the file content on the target system. This may cause a large amount of information leakage. Version 1.5.0 has a patch for this issue.

Affected configurations

Vulners
Node
go1panelMatchv1.4.3
VendorProductVersionCPE
go1panelv1.4.3cpe:2.3:a:go:1panel:v1.4.3:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

24.0%

Related for GITLAB-4C35946F93393FEDCAC9E7799CCE262E