CVE-2024-30257
EUVD-2024-112718.04.2024, 15:15
1Panel is an open source Linux server operation and maintenance management panel. The password verification in the source code uses the != symbol instead hmac.Equal. This may lead to a timing attack vulnerability. This vulnerability is fixed in 1.10.3-lts.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fit2cloud | 1panel | 𝑥 < 1.10.3-lts |
𝑥
= Vulnerable software versions
References