CVE-2024-30257
18.04.2024, 15:15
1Panel is an open source Linux server operation and maintenance management panel. The password verification in the source code uses the != symbol instead hmac.Equal. This may lead to a timing attack vulnerability. This vulnerability is fixed in 1.10.3-lts.Enginsight
Vendor | Product | Version |
---|---|---|
fit2cloud | 1panel | 𝑥 < 1.10.3-lts |
𝑥
= Vulnerable software versions
References