Landian News Technology
Proxmox VE 7~8.0.3 contains a high-severity vulnerability allowing passwordless login; real attacks and ransomware incidents have already occurred
#Security News Urgent security alert: PVE 7.x~8.0.3 contains a high-severity passwordless-authentication vulnerability that allows attackers to obtain root privileges without a password. These versions are no longer supported and therefore have no patch. Proxmox VE officials have confirmed that user-installed instances have already been attacked and ransomware has been deployed. The current temporary emergency measure is to modify AccessControl.pm to force verification of the authenticity of the tfa-challenge signature, and then restart the relevant services. It is also important to note that exploitation methods for the vulnerability have been publicly disclosed online, and related attacks are expected to grow rapidly. Users are advised to upgrade PVE immediately. Read the full article: https://ourl.co/126596