New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
PSA: Update your Proxmox VE installations (Authentication bypass in EOL Proxmox VE releases)
https://forum.proxmox.com/posts/867929/
TL;DR:
- Older, EOL versions of Proxmox VE have an actively exploited vulnerability with the
libpve-access-controlpackage (Affected: >= 7.0-7 and < 8.0.4) - If 8006 WebUI/API is exposed to public Internet, attackers can bypass passwords entirely to authenticate as root, due to a cursed 2FA implementation
- Current supported PVE versions (9.x) are completely safe
- If you are still running PVE 7.x-8.0.3, restrict access to port 8006 and upgrade immediately

Comments
I was one of the original reporters in the advisory.
Sharing my repo with the fixes, root cause analysis, and detection rules: https://github.com/neeythann/Proxmox-VE-7-RCE
@trumvps is this what you mentioned?
oh, it doesn't affect much anyway
edit: okay chatgpt scheduled task just sent me an update, which the api /access/ticket can be bypassed completely
Will these make it secure if im unable to patch mine?
I just don't open Proxmox to the internet.
Well, glad nobody is using EOL software
I didn't upgrade my private proxmox nodes yet....
Luckly, Proxmox is firewalled anyway.
Its time to upgrade today I guess.
I just put my Web UI behind cloudflared tunnel and have a one time pin to it...
Please dont scan my IPs I think one of mine is running EOL version
Nevermind, the server just hang up while upgrading it.
Fuck me, but its Safe now, until someone at OVH reboots the server.