Medium SEVERITY — Security Update

PVE 8 GUI session security improvements

Hardening updates were released for web interface session management and CSRF validations.

Platform
Proxmox VE
Version
PVE 8 / Bookworm tabanlı
Published
15 November 2023
Views
4
Primary source: Review the official advisory at forum.proxmox.com Kaynağa Git

Scope

  • Session cookie SameSite and rotation improvements
  • Tightening of CSRF token validation
  • Additional security headers for pveproxy

Recommendation: Continue to expose GUI access only via management VLAN/VPN — port 8006 should remain closed to the internet.

Proxmox VE — Related Advisories

VIEW ALL →