CVE-2023-39964
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Aug 10, 2023
Updated: Sep 8, 2023
CWE ID 22
Summary
CVE-2023-39964 is a vulnerability affecting version 1.4.3 of the 1Panel open source Linux server management tool. An attacker can exploit this issue to read arbitrary important configuration files on the server through unfiltered request parameters in the `api/v1/file.go` file's `LoadFromFile` function. This background arbitrary file reading vulnerability poses a significant security risk. To mitigate this issue, users are advised to upgrade to version 1.5.0, which includes a patch for the problem.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share