¡¾·ì϶¹«¸æ¡¿1Panel Agent Ö¤ÊéÑéÖ¤ÈÆ¹ýRCE·ì϶(CVE-2025-54424)
°ä²¼¹¦·ò 2025-08-05Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | 1Panel Agent Ö¤ÊéÑéÖ¤ÈÆ¹ýRCE·ì϶ | ||
CVE ID | CVE-2025-54424 | ||
·ì϶ÀàÐÍ | RCE | ·¢ÏÖ¹¦·ò | 2025-08-05 |
·ì϶ÆÀ·Ö | 8.1 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
1PanelÊÇÒ»¿î¿ªÔ´µÄLinux·þÎñÆ÷ÔËάÖÎÀíÃæ°å£¬Ö§³Öͨ¹ý¿ÉÊÓ»¯½çÃæÖÎÀíÍøÕ¾¡¢Êý¾Ý¿â¡¢DockerÈÝÆ÷¡¢SSLÖ¤Êé¡¢·À»ðǽµÈÖ°ÄÜ¡£Ëüѡȡǰºó¶Ë·ÖÀë¼Ü¹¹£¬Ö§³Ö¶à½ÚµãÖÎÀí£¬¾ß±¸¼ò½àÒ×Óᢰ²È«ÐԸߡ¢×Ô¶¯»¯Ë®Æ½¸ßµµÌص㣬ºÏÓÃÓÚÖÐÓ×ÐÍÆóÒµ»ò¿ª·¢Õß½øÐзþÎñÆ÷¼¯³ÉÔËάÖÎÀí¡£
2025Äê8ÔÂ5ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½1Panel Agent´æÔÚÖ¤ÊéÑéÖ¤ÈÆ¹ýµ¼ÖµÄÔ¶³ÌºÅÁîÖ´ÐУ¨RCE£©·ì϶¡£¸Ã·ì϶ӰÏì1Panel v2°æ±¾ÒýÈëµÄCore-Agent¼Ü¹¹£¬Ë«·½Í¨¹ýHTTPS½øÐÐͨѶʱʹÓÃtls.RequireAnyClientCert½øÐÐÖ¤ÊéУÑ飬½ö²é³Ö¤ÊéµÄCN×Ö¶ÎΪpanel_client£¬Î´¶ÔÖ¤ÊéÇ©·¢»ú¹¹½øÐÐÑéÖ¤¡£¹¥»÷Õß¿Éͨ¹ýαÔìºÏ·¨ÌåʽµÄ¿Í»§¶ËÖ¤ÊéÈÆ¹ýÉí·ÝÈÏÖ¤£¬½ø¶ø½Ó¼û¶à¸ö¸ßȨÏÞWebSocket½Ó¿Ú£¬ÊµÏÖÃô¸ÐÐÅÏ¢»ñÈ¡ÓëÔ¶³ÌºÅÁîÖ´ÐС£·ì϶ÆÀ·Ö8.1·Ö£¬·ì϶¼¶±ð¸ßΣ¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/1Panel-dev/1Panel/releases


¾©¹«Íø°²±¸11010802024551ºÅ