Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

VULNERABILITY v.0.9.8-26 : when new update will be available?

General questions about VestaCP
Post Reply
  • Print view
Advanced search
5 posts • Page 1 of 1
sauvegardezvous99
Posts: 25
Joined: Mon Nov 24, 2014 11:48 pm

VULNERABILITY v.0.9.8-26 : when new update will be available?
  • Quote

Post by sauvegardezvous99 » Thu Dec 10, 2020 3:34 am

hello,

2 serious new disclosures have been published here :

https://www.exploit-db.com/exploits/49220
https://www.exploit-db.com/exploits/49219

Does the team work on it ? do you provide a patch soon ?

best,
Top

sauvegardezvous99
Posts: 25
Joined: Mon Nov 24, 2014 11:48 pm

Re: VULNERABILITY v.0.9.8-26 : when new update will be available?
  • Quote

Post by sauvegardezvous99 » Thu Dec 10, 2020 3:43 am

ok the project is dead now : https://github.com/serghey-rodin/vesta/issues/2006
Top

darkleech
Posts: 120
Joined: Sun Aug 03, 2014 10:46 am

Re: VULNERABILITY v.0.9.8-26 : when new update will be available?
  • Quote

Post by darkleech » Fri Dec 11, 2020 1:29 pm

Vesta is dead
Top

eris
Posts: 34
Joined: Fri Jun 26, 2020 9:25 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: VULNERABILITY v.0.9.8-26 : when new update will be available?
  • Quote

Post by eris » Sat Dec 12, 2020 12:20 am

https://www.vulnerability-lab.com/get_c ... hp?id=2239

A 3rd one

All are mainly XXS issues. So no real risks how ever need to be fixed
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: VULNERABILITY v.0.9.8-26 : when new update will be available?
  • Quote

Post by dpeca » Sat Dec 12, 2020 1:44 pm

Only XSS issue with /list/rrd/ is real issue (and as all other XSS isues, it's not so dangerous).
First two issues (downloading someone other's backup and exploiting loginas function) are not real issues, I mean, you can exploit it only if you are already logged in as admin... I don't need to explain why it's useless.

However, myVestaCP already fixed all three issues, and HestiaCP will release fixes in next few days (they already patched code too, just it will not go to public repo instantly, and btw they don't have XSS issue with RRD period).
No need to hurry, since those issues are really trivial.
Top


Post Reply
  • Print view

5 posts • Page 1 of 1

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password