VU#243636: VPS.org one-click d... Note

VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities

VPS.org's one-click deployment templates suffer from multiple vulnerabilities due to static configurations. The Supabase template exposes PostgreSQL to all network interfaces with a hard-coded password, allowing remote attackers to gain superuser access. This unpatched vulnerability enables data theft, modification, denial of service, and persistence. The Zulip template also has a hard-coded application key and a default database password, facilitating session forgery and authentication bypass. Furthermore, it defaults to unencrypted HTTP traffic, exposing sensitive data. These vulnerabilities grant attackers total control over affected systems. VPS.org has not yet released a patch for these issues. Users are strongly advised to change default passwords and secrets before production deployment. Implementing firewalls, network segmentation, and HTTPS are crucial mitigation steps. Simon Gajdosik reported these vulnerabilities.