CVE-2024-24768
Published Feb 5, 2024
Last updated 9 months ago
Overview
- Description
- 1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure keyword, which may cause the cookie to be sent in plain text if accessed using HTTP. This issue has been patched in version 1.9.6.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:fit2cloud:1panel:1.9.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B112F28A-9D5B-45B8-8201-1FA859875E7F" } ], "operator": "OR" } ] } ]