ajenti@1.0.0 vulnerabilities

The server administration panel

Direct Vulnerabilities

Known vulnerabilities in the ajenti package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Remote Code Execution (RCE)

ajenti is a Linux & BSD web admin panel.

Affected versions of this package are vulnerable to Remote Code Execution (RCE) in os auth provider.

How to fix Remote Code Execution (RCE)?

A fix was pushed into the master branch but not yet published.

[0,)
  • M
Cross-site Scripting (XSS)

ajenti is a Linux & BSD web admin panel.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). It is possible for remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality available within plugins/main/content/js/ajenti.coffee.

How to fix Cross-site Scripting (XSS)?

Upgrade ajenti to version 1.2.15 or higher.

[,1.2.15)
  • M
Cross-site Scripting (XSS)

ajenti is a Linux & BSD web admin panel.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks via a filename that is mishandled in File Manager.

How to fix Cross-site Scripting (XSS)?

There is no fix version for ajenti.

[0,)
  • M
Cross-site Scripting (XSS)

ajenti is the server administration panel

Multiple Cross-site Scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) resources.js or (2) resources.css in ajenti:static/, related to the traceback page.

[,1.2.21.6)
  • M
Directory Traversal

ajenti is the server administration panel Affected versions of this package are Directory Traversal due to no validation whether the path in the users request points to a static file. This allows an attacker to read any file or folder with system level privileges.

[0.9.29,1.2.17)