Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

PSA: Update your Proxmox VE installations (Authentication bypass in EOL Proxmox VE releases​)

https://forum.proxmox.com/posts/867929/

TL;DR:

  • Older, EOL versions of Proxmox VE have an actively exploited vulnerability with the libpve-access-control package (Affected: >= 7.0-7 and < 8.0.4)
  • If 8006 WebUI/API is exposed to public Internet, attackers can bypass passwords entirely to authenticate as root, due to a cursed 2FA implementation
  • Current supported PVE versions (9.x) are completely safe
  • If you are still running PVE 7.x-8.0.3, restrict access to port 8006 and upgrade immediately
Thanked by 4oloke rpqu Murv forest

Comments

Sign In or Register to comment.