CVE-2024-24768
MEDIUMDescription
1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure keyword, which may cause the cookie to be sent in plain text if accessed using HTTP. This issue has been patched in version 1.9.6.
Is your site exposed to CVE-2024-24768?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| fit2cloud | 1panel |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-24768? +
How severe is CVE-2024-24768? +
What products are affected by CVE-2024-24768? +
How do I check if I'm vulnerable to CVE-2024-24768? +
Related Vulnerabilities
FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.
Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka …
A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of …
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue is some …
1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue …
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access …