blob: 13190156598a15e38497cfc7f0a10857b00e86ab [file] [log] [blame]
id: GO-2023-1940
modules:
- module: github.com/1Panel-dev/1Panel
versions:
- fixed: 1.4.3
vulnerable_at: 1.4.2
summary: 1Panel command injection vulnerability in Firewall ip functionality in github.com/1Panel-dev/1Panel
cves:
- CVE-2023-37477
ghsas:
- GHSA-p9xf-74xh-mhw5
references:
- advisory: https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-p9xf-74xh-mhw5
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-37477
- fix: https://github.com/1Panel-dev/1Panel/commit/e17b80cff4975ee343568ff526b62319f499005d
- web: https://github.com/1Panel-dev/1Panel/releases/tag/v1.4.3
source:
id: GHSA-p9xf-74xh-mhw5
created: 2024-08-20T11:53:19.224251-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE