Filtered by vendor Fit2cloud
Subscribe
Total
44 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-39965 | 1 Fit2cloud | 1 1panel | 2024-02-28 | N/A | 4.3 MEDIUM |
1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, authenticated attackers can download arbitrary files through the API interface. This code has unauthorized access. Attackers can freely download the file content on the target system. This may cause a large amount of information leakage. Version 1.5.0 has a patch for this issue. | |||||
CVE-2023-46123 | 1 Fit2cloud | 1 Jumpserver | 2024-02-28 | N/A | 5.3 MEDIUM |
jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications. A flaw in the Core API allows attackers to bypass password brute-force protections by spoofing arbitrary IP addresses. By exploiting this vulnerability, attackers can effectively make unlimited password attempts by altering their apparent IP address for each request. This vulnerability has been patched in version 3.8.0. | |||||
CVE-2023-39964 | 1 Fit2cloud | 1 1panel | 2024-02-28 | N/A | 7.5 HIGH |
1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads allow an attacker to read arbitrary important configuration files on the server. In the `api/v1/file.go` file, there is a function called `LoadFromFile`, which directly reads the file by obtaining the requested path `parameter[path]`. The request parameters are not filtered, resulting in a background arbitrary file reading vulnerability. Version 1.5.0 has a patch for this issue. | |||||
CVE-2023-38692 | 1 Fit2cloud | 1 Cloudexplorer Lite | 2024-02-28 | N/A | 9.8 CRITICAL |
CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the installation function in module management. The vulnerability has been fixed in v1.3.1. There are no known workarounds aside from upgrading. | |||||
CVE-2023-42818 | 1 Fit2cloud | 1 Jumpserver | 2024-02-28 | N/A | 9.8 CRITICAL |
JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An attacker could exploit a vulnerability by utilizing a disclosed public key to attempt brute-force authentication against the SSH service This issue has been patched in versions 3.6.5 and 3.5.6. Users are advised to upgrade. There are no known workarounds for this issue. | |||||
CVE-2023-42147 | 1 Fit2cloud | 1 Cloudexplorer Lite | 2024-02-28 | N/A | 7.5 HIGH |
An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component. | |||||
CVE-2023-39519 | 1 Fit2cloud | 1 Cloudexplorer Lite | 2024-02-28 | N/A | 4.9 MEDIUM |
Cloud Explorer Lite is an open source cloud management platform. Prior to version 1.4.0, there is a risk of sensitive information leakage in the user information acquisition of CloudExplorer Lite. The vulnerability has been fixed in version 1.4.0. | |||||
CVE-2023-32311 | 1 Fit2cloud | 1 Cloudexplorer | 2024-02-28 | N/A | 4.3 MEDIUM |
CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organization/workspace permissions are not properly checked. This allows users to add themselves to any organization. This vulnerability has been fixed in v1.1.0. Users are advised to upgrade. There are no known workarounds for this issue. | |||||
CVE-2023-2845 | 1 Fit2cloud | 1 Cloudexplorer Lite | 2024-02-28 | N/A | 8.1 HIGH |
Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. | |||||
CVE-2023-36457 | 1 Fit2cloud | 1 1panel | 2024-02-28 | N/A | 8.8 HIGH |
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payload to achieve command injection when adding container repositories. The vulnerability has been fixed in v1.3.6. | |||||
CVE-2023-32316 | 1 Fit2cloud | 1 Cloudexplorer | 2024-02-28 | N/A | 4.3 MEDIUM |
CloudExplorer Lite is an open source cloud management tool. In affected versions users can add themselves to any organization in CloudExplorer Lite. This is due to a missing permission check on the user profile. It is recommended to upgrade the version to v1.1.0. There are no known workarounds for this vulnerability. | |||||
CVE-2023-3423 | 1 Fit2cloud | 1 Cloudexplorer Lite | 2024-02-28 | N/A | 8.8 HIGH |
Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0. | |||||
CVE-2023-2844 | 1 Fit2cloud | 1 Cloudexplorer Lite | 2024-02-28 | N/A | 4.9 MEDIUM |
Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. | |||||
CVE-2023-36458 | 1 Fit2cloud | 1 1panel | 2024-02-28 | N/A | 8.8 HIGH |
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal. The vulnerability has been fixed in v1.3.6. | |||||
CVE-2022-42225 | 1 Fit2cloud | 1 Lina | 2024-02-28 | N/A | 5.4 MEDIUM |
Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission. | |||||
CVE-2023-34240 | 1 Fit2cloud | 1 Cloudexplorer Lite | 2024-02-28 | N/A | 9.8 CRITICAL |
Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and compromise system security. Versions of cloudexplorer-lite prior to 1.2.0 did not enforce strong passwords. This vulnerability has been fixed in version 1.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |||||
CVE-2023-22463 | 1 Fit2cloud | 1 Kubepi | 2024-02-28 | N/A | 9.8 CRITICAL |
KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This means that an attacker can forge any jwt token to take over the administrator account of any online project. Furthermore, they may use the administrator to take over the k8s cluster of the target enterprise. `session.go`, the use of hard-coded JwtSigKey, allows an attacker to use this value to forge jwt tokens arbitrarily. The JwtSigKey is confidential and should not be hard-coded in the code. The vulnerability has been fixed in 1.6.3. In the patch, JWT key is specified in app.yml. If the user leaves it blank, a random key will be used. There are no workarounds aside from upgrading. | |||||
CVE-2023-28110 | 1 Fit2cloud | 2 Jumpserver, Koko | 2024-02-28 | N/A | 9.9 CRITICAL |
Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. Prior to version 2.28.8, using illegal tokens to connect to a Kubernetes cluster through Koko can result in the execution of dangerous commands that may disrupt the Koko container environment and affect normal usage. The vulnerability has been fixed in v2.28.8. | |||||
CVE-2023-22479 | 1 Fit2cloud | 1 Kubepi | 2024-02-28 | N/A | 6.5 MEDIUM |
KubePi is a modern Kubernetes panel. A session fixation attack allows an attacker to hijack a legitimate user session, versions 1.6.3 and below are susceptible. A patch will be released in version 1.6.4. | |||||
CVE-2023-22480 | 1 Fit2cloud | 1 Kubeoperator | 2024-02-28 | N/A | 9.8 CRITICAL |
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4. |