PVE 8 GUI session security improvements
Hardening updates were released for web interface session management and CSRF validations.
Hardening updates were released for web interface session management and CSRF validations.
SameSite and rotation improvementspveproxyRecommendation: Continue to expose GUI access only via management VLAN/VPN — port 8006 should remain closed to the internet.
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification
Proxmox Virtual Environment now available for 64-bit ARM (arm64)! is available.