mirror of
https://github.com/aaPanel/aaPanel.git
synced 2026-08-17 21:25:47 +02:00
Since version 7.7.0, we recommend yours update python to 3.12. [+] Using nginx technology to load static files improves access speed [+] Refactor homepage, website, FTP, and database using vue3 [+] Table loading changed to skeleton screen [+] Add Website statistics-v2 professional plug-in [+] Add Home page - top 5 resource occupancy [+] Add protection for Files management (requires Tamper-proof for Enterprise 3.7) [+] Website, FTP, Databases page add program status [+] Add FTP log analysis (only supports Centos) [+] Add password-free login to phpMyAdmin [+] Add Proxy Project in Website (Supported when web service uses Nginx) [+] Add WP Toolkit (Pro version only) [+] Redesigned Docker module [+] Add WP Toolkit Protection [+] Add WP Toolkit Backup and Restore [+] Add WP Toolkit Migrated [+] Add WP Toolkit Clone site (supports new domain and subdomain) [+] Add WP Toolkit Create site from backup of other panel [+] Add WP Toolkit support for Cron automatic backup (only save Local disk) [+] Add WP Toolkit operation log [+] Add Integrity check for WP Toolkit [+] Add WP Toolkit plug-in management and themes management [*] Optimize phpMyAdmin formula access method [*] Optimize Home page PHP display problem [*] Optimize jump to the login interface after the login expires [*] Optimize automatic renewal of SSL at some times [*] Optimize Let's Encrypt to increase application success rate [-] Fix Logs Audit cannot be opened [-] Fix apache URL rewrite issue [-] Fix phpmyadmin installation problem [-] Fix the problem that some servers cannot install software [-] Fix upload file error [-] Fix left menu hiding problem [-] Fix aaPanel Mobile QR code display problem [-] Fix problem that third-party plug-ins are not displayed in the App Store [-] Fix issue where the menu bar is blank when opening new tabs [-] Fixed panel not being accessible in some cases [-] Fix the issue where Curl warning caused the inability to apply for SSL [-] Fix Quota issues for Website, FTP, Databases [-] Fix file interface display problem on mobile terminal
115 lines
3.5 KiB
Python
115 lines
3.5 KiB
Python
#coding: utf-8
|
|
# +-------------------------------------------------------------------
|
|
# | aaPanel
|
|
# +-------------------------------------------------------------------
|
|
# | Copyright (c) 2015-2099 aaPanel(www.aapanel.com) All rights reserved.
|
|
# +-------------------------------------------------------------------
|
|
# | Author: hwliang <hwl@aapanel.com>
|
|
# +-------------------------------------------------------------------
|
|
|
|
#--------------------------------
|
|
# 修复polkit提权漏洞(CVE-2021-4034)
|
|
#--------------------------------
|
|
|
|
import os,sys
|
|
os.chdir("/www/server/panel")
|
|
sys.path.insert(0,'class/')
|
|
import public
|
|
upgrade_log_file = '/www/server/panel/logs/upgrade_polkit.log'
|
|
log_msg = "A polkit (CVE-2021-4034) privilege escalation vulnerability has been detected in the system and has been fixed for you!"
|
|
|
|
|
|
def write_log(msg):
|
|
global upgrade_log_file
|
|
public.writeFile(upgrade_log_file,"[{}] - {}".format(public.format_date(),msg),'a+')
|
|
|
|
def is_yum():
|
|
if os.path.exists('/usr/bin/yum'):
|
|
return True
|
|
return False
|
|
|
|
def is_dnf():
|
|
if os.path.exists('/usr/bin/dnf'):
|
|
return True
|
|
return False
|
|
|
|
def is_apt():
|
|
if os.path.exists('/usr/bin/apt'):
|
|
return True
|
|
return False
|
|
|
|
def upgrade_by_yum():
|
|
global upgrade_log_file,log_msg
|
|
res = public.ExecShell("rpm -q polkit")[0]
|
|
if res.startswith('polkit-'):
|
|
os.system("yum -y update polkit &> {}".format(upgrade_log_file))
|
|
res2 = public.ExecShell("rpm -q polkit")[0]
|
|
if res == res2:
|
|
write_log("Repair failed, please execute the command manually: yum -y update polkit")
|
|
return False
|
|
public.WriteLog('Vulnerability Repair',log_msg)
|
|
return True
|
|
return False
|
|
|
|
def upgrade_by_dnf():
|
|
global upgrade_log_file,log_msg
|
|
res = public.ExecShell("rpm -q polkit")[0]
|
|
if res.startswith('polkit-'):
|
|
os.system("dnf -y update polkit &> {}".format(upgrade_log_file))
|
|
res2 = public.ExecShell("rpm -q polkit")[0]
|
|
if res == res2:
|
|
write_log("Repair failed, please execute the command manually: dnf -y update polkit")
|
|
return False
|
|
public.WriteLog('Vulnerability Repair',log_msg)
|
|
return True
|
|
return False
|
|
|
|
|
|
def upgrade_by_apt():
|
|
global upgrade_log_file,log_msg
|
|
res = public.ExecShell("dpkg -l policykit-1|grep policykit-1|awk '{print $3}'")[0]
|
|
if res.startswith('0.105'):
|
|
os.system("apt-get -y install policykit-1 &> {}".format(upgrade_log_file))
|
|
res2 = public.ExecShell("dpkg -l policykit-1|grep policykit-1|awk '{print $3}'")[0]
|
|
if res == res2:
|
|
write_log("Repair failed, please execute the command manually: apt-get -y install policykit-1")
|
|
return False
|
|
public.WriteLog('Vulnerability Repair',log_msg)
|
|
return True
|
|
return False
|
|
|
|
def check():
|
|
tip_file = '/www/server/panel/data/upgrade_polkit.pl'
|
|
if os.path.exists(tip_file):
|
|
return
|
|
write_log("Fixing the privilege escalation vulnerability of polkit (CVE-2021-4034)...")
|
|
if is_yum():
|
|
upgrade_by_yum()
|
|
elif is_dnf():
|
|
upgrade_by_dnf()
|
|
elif is_apt():
|
|
upgrade_by_apt()
|
|
else:
|
|
return
|
|
|
|
public.writeFile(tip_file,'True')
|
|
|
|
|
|
if __name__ == "__main__":
|
|
tip_file = '/www/server/panel/data/upgrade_polkit_run.pl'
|
|
if os.path.exists(tip_file):
|
|
print("The program is running, exit!")
|
|
sys.exit(1)
|
|
|
|
public.writeFile(tip_file,'True')
|
|
try:
|
|
check()
|
|
except:
|
|
pass
|
|
finally:
|
|
if os.path.exists(tip_file): os.remove(tip_file)
|
|
|
|
|
|
|
|
|