Files
aaPanel/script/polkit_upgrade.py
Jack ed55fa708d Update to 7.7.0
Since version 7.7.0, we recommend yours update python to 3.12.

[+] Using nginx technology to load static files improves access speed
[+] Refactor homepage, website, FTP, and database using vue3
[+] Table loading changed to skeleton screen
[+] Add Website statistics-v2 professional plug-in
[+] Add Home page - top 5 resource occupancy
[+] Add protection for Files management (requires Tamper-proof for Enterprise 3.7)
[+] Website, FTP, Databases page add program status
[+] Add FTP log analysis (only supports Centos)
[+] Add password-free login to phpMyAdmin
[+] Add Proxy Project in Website (Supported when web service uses Nginx)
[+] Add WP Toolkit (Pro version only)
[+] Redesigned Docker module
[+] Add WP Toolkit Protection
[+] Add WP Toolkit Backup and Restore
[+] Add WP Toolkit Migrated
[+] Add WP Toolkit Clone site (supports new domain and subdomain)
[+] Add WP Toolkit Create site from backup of other panel
[+] Add WP Toolkit support for Cron automatic backup (only save Local disk)
[+] Add WP Toolkit operation log
[+] Add Integrity check for WP Toolkit
[+] Add WP Toolkit plug-in management and themes management

[*] Optimize phpMyAdmin formula access method
[*] Optimize Home page PHP display problem
[*] Optimize jump to the login interface after the login expires
[*] Optimize automatic renewal of SSL at some times
[*] Optimize Let's Encrypt to increase application success rate

[-] Fix Logs Audit cannot be opened
[-] Fix apache URL rewrite issue
[-] Fix phpmyadmin installation problem
[-] Fix the problem that some servers cannot install software
[-] Fix upload file error
[-] Fix left menu hiding problem
[-] Fix aaPanel Mobile QR code display problem
[-] Fix problem that third-party plug-ins are not displayed in the App Store
[-] Fix issue where the menu bar is blank when opening new tabs
[-] Fixed panel not being accessible in some cases
[-] Fix the issue where Curl warning caused the inability to apply for SSL
[-] Fix Quota issues for Website, FTP, Databases
[-] Fix file interface display problem on mobile terminal
2024-07-19 11:25:10 +08:00

115 lines
3.5 KiB
Python

#coding: utf-8
# +-------------------------------------------------------------------
# | aaPanel
# +-------------------------------------------------------------------
# | Copyright (c) 2015-2099 aaPanel(www.aapanel.com) All rights reserved.
# +-------------------------------------------------------------------
# | Author: hwliang <hwl@aapanel.com>
# +-------------------------------------------------------------------
#--------------------------------
# 修复polkit提权漏洞(CVE-2021-4034)
#--------------------------------
import os,sys
os.chdir("/www/server/panel")
sys.path.insert(0,'class/')
import public
upgrade_log_file = '/www/server/panel/logs/upgrade_polkit.log'
log_msg = "A polkit (CVE-2021-4034) privilege escalation vulnerability has been detected in the system and has been fixed for you!"
def write_log(msg):
global upgrade_log_file
public.writeFile(upgrade_log_file,"[{}] - {}".format(public.format_date(),msg),'a+')
def is_yum():
if os.path.exists('/usr/bin/yum'):
return True
return False
def is_dnf():
if os.path.exists('/usr/bin/dnf'):
return True
return False
def is_apt():
if os.path.exists('/usr/bin/apt'):
return True
return False
def upgrade_by_yum():
global upgrade_log_file,log_msg
res = public.ExecShell("rpm -q polkit")[0]
if res.startswith('polkit-'):
os.system("yum -y update polkit &> {}".format(upgrade_log_file))
res2 = public.ExecShell("rpm -q polkit")[0]
if res == res2:
write_log("Repair failed, please execute the command manually: yum -y update polkit")
return False
public.WriteLog('Vulnerability Repair',log_msg)
return True
return False
def upgrade_by_dnf():
global upgrade_log_file,log_msg
res = public.ExecShell("rpm -q polkit")[0]
if res.startswith('polkit-'):
os.system("dnf -y update polkit &> {}".format(upgrade_log_file))
res2 = public.ExecShell("rpm -q polkit")[0]
if res == res2:
write_log("Repair failed, please execute the command manually: dnf -y update polkit")
return False
public.WriteLog('Vulnerability Repair',log_msg)
return True
return False
def upgrade_by_apt():
global upgrade_log_file,log_msg
res = public.ExecShell("dpkg -l policykit-1|grep policykit-1|awk '{print $3}'")[0]
if res.startswith('0.105'):
os.system("apt-get -y install policykit-1 &> {}".format(upgrade_log_file))
res2 = public.ExecShell("dpkg -l policykit-1|grep policykit-1|awk '{print $3}'")[0]
if res == res2:
write_log("Repair failed, please execute the command manually: apt-get -y install policykit-1")
return False
public.WriteLog('Vulnerability Repair',log_msg)
return True
return False
def check():
tip_file = '/www/server/panel/data/upgrade_polkit.pl'
if os.path.exists(tip_file):
return
write_log("Fixing the privilege escalation vulnerability of polkit (CVE-2021-4034)...")
if is_yum():
upgrade_by_yum()
elif is_dnf():
upgrade_by_dnf()
elif is_apt():
upgrade_by_apt()
else:
return
public.writeFile(tip_file,'True')
if __name__ == "__main__":
tip_file = '/www/server/panel/data/upgrade_polkit_run.pl'
if os.path.exists(tip_file):
print("The program is running, exit!")
sys.exit(1)
public.writeFile(tip_file,'True')
try:
check()
except:
pass
finally:
if os.path.exists(tip_file): os.remove(tip_file)