Proxmox VE 7 support ended (EOL)
Security updates for the PVE 7 series have stopped; remaining hosts must be migrated to the PVE 8/9 line.
Security updates for the PVE 7 series have stopped; remaining hosts must be migrated to the PVE 8/9 line.
Proxmox VE 7 için resmi güvenlik ve hata düzeltme desteği 31 July 2024 itibarıyla sona erdi.
Upgrade plan for remaining PVE 7 hosts:
1. Full verification of PBS backups
2. Archiving the pve7to8 --full check output
3. In-place upgrade during a maintenance window
Once no hosts running PVE 7 remain, this release can be disabled from the panel with a single click.
A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different user for a different VM.