Release
Proxmox VE 7.4
Proxmox VE · 1 target · 1 artifact
Release Facts
- Version
- 7.4
- Date
- Architectures
- -
- Editions
- -
- Variants
- -
- Protocols
- https, magnet
Quality
- Targets
- 1
- Artifacts
- 1
- Checksums
- 1/1
- Average confidence
- 0.85
- CVEs
- 2
Artifacts
| Artifact | Media | Size | Protocols | Checksums | Quality |
|---|---|---|---|---|---|
| proxmox-ve_7.4-1.iso | iso | unknown | https, magnet | 1 | 0.85 |
Related CVEs
- CVE-2023-43320
HIGH · An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component.
- CVE-2023-54391
CRITICAL · Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.