CyberRota Analysis
AI-GeneratedPortainer Community Edition versions 2.39.0 to 2.39.3 and 2.40.0 to 2.43.0 are vulnerable due to unauthenticated access to restore and administrator initialization endpoints during the initial setup window, potentially allowing attackers to restore malicious backups or create an admin account. This vulnerability could lead to unauthorized administrative access, compromising the security of Docker and Kubernetes environments. Organizations using affected versions should prioritize upgrading to versions 2.39.4 or 2.43.0 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoints (/api/restore and /api/users/admin/init) remain accessible during the five-minute setup window for uninitialized instances, allowing a network attacker to restore a crafted backup or create the first administrator account and gain full administrative access. This issue is fixed in versions 2.39.4 and 2.43.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)