cbcvebase.
CVE-2024-24768
published 2024-02-05

CVE-2024-24768: 1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure keyword…

PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.30%
22.0th percentile
1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure keyword, which may cause the cookie to be sent in plain text if accessed using HTTP. This issue has been patched in version 1.9.6.

Affected

3 ranges
VendorProductVersion rangeFixed in
1panel-dev1panel<= 1.9.5
fit2cloud1panel
github.com1panel-dev_1panel>= 0 < 1.9.61.9.6
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.