—
GO-2024-2636
1Panel is vulnerable to command injection in github.com/1Panel-dev/1Panel
Quick fix
GO-2024-2636 — github.com/1Panel-dev/1Panel: upgrade to the fixed version with the command below.
go get github.com/1Panel-dev/1Panel@v1.10.1-ltsDetails
1Panel is vulnerable to command injection in github.com/1Panel-dev/1Panel
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/1Panel-dev/1Panel
Introduced in:
0Fixed in: 1.10.1-ltsFix
go get github.com/1Panel-dev/1Panel@v1.10.1-ltsReferences
- https://github.com/advisories/GHSA-x2vg-5wrf-vj6v[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-2352[ADVISORY]
- https://github.com/1Panel-dev/1Panel/pull/4131[FIX]
- https://github.com/1Panel-dev/1Panel/pull/4131#issue-2176105990[FIX]
- https://github.com/1Panel-dev/1Panel/pull/4131/commits/0edd7a9f6f5100aab98a0ea6e5deedff7700396c[FIX]
- https://vuldb.com/?ctiid.256304[WEB]
- https://vuldb.com/?id.256304[WEB]