GHSA-85cf-gj29-f555
Dashboard / Vulnerabilities / GHSA-85cf-gj29-f555
GHSA-85cf-gj29-f555
Summary: 1Panel Arbitrary File Download vulnerability
Details: ### Summary Any file downloading vulnerability exists in 1Panel backend. ### Details Authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access.  ### PoC payload: POST /api/v1/files/download/bypath HTTP/1.1 Host: ip Content-Type: application/json {"path":"/etc/passwd"}  ### Impact Attackers can freely download the file content on the target system. This will be caused a large amount of information leakage.
References: https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-85cf-gj29-f555, https://nvd.nist.gov/vuln/detail/CVE-2023-39965, https://github.com/1Panel-dev/1Panel, https://github.com/1Panel-dev/1Panel/releases/tag/v1.5.0
Affected packages
Package
Name: github.com/1Panel-dev/1Panel
Purl: pkg:golang/github.com/1Panel-dev/1Panel
Affected ranges
Type: SEMVER
Events:
