Vulnerabilities > CVE-2024-30257 - Information Exposure Through Discrepancy vulnerability in Fit2Cloud 1Panel

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
high complexity
fit2cloud
CWE-203

Summary

1Panel is an open source Linux server operation and maintenance management panel. The password verification in the source code uses the != symbol instead hmac.Equal. This may lead to a timing attack vulnerability. This vulnerability is fixed in 1.10.3-lts.

Common Weakness Enumeration (CWE)