Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/1Panel-dev/1Panel
  4. ›
  5. CVE-2024-39907

CVE-2024-39907: 1Panel has an SQL injection issue related to the orderBy clause

July 18, 2024

There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The proof is as follows

References

  • github.com/1Panel-dev/1Panel
  • github.com/1Panel-dev/1Panel/commit/ff549a47937c1314e6ee08453a1d2128242440cd
  • github.com/1Panel-dev/1Panel/security/advisories/GHSA-5grx-v727-qmq6
  • github.com/advisories/GHSA-5grx-v727-qmq6
  • nvd.nist.gov/vuln/detail/CVE-2024-39907

Code Behaviors & Features

Detect and mitigate CVE-2024-39907 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.10.12-tls

Fixed versions

  • 1.10.12-tls

Solution

Upgrade to version 1.10.12-tls or above.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Source file

go/github.com/1Panel-dev/1Panel/CVE-2024-39907.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:34 +0000.