CVE-2021-30070
Dashboard / Vulnerabilities / CVE-2021-30070
CVE-2021-30070
Published: 18 Aug 2022Last Modified: 7 Aug 2026
Summary:
Details: An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter in the update request being transmitted to the operating system's package manager.
References: https://github.com/hestiacp/hestiacp/commit/27556a9a43aeaf308b33be224c2e70f2011574e6, https://github.com/hestiacp/hestiacp/commit/9a1fccd37f2842fdf96ffb48895c4bfa9788c469
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
1.3.4
1.3.2
1.3.1
1.3.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
