First published: Tue Aug 06 2019(Updated: )
cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=11.51.9999.98<11.52.6.2 | |
Cpanel Cpanel | >=11.54.0.0<11.54.0.26 | |
Cpanel Cpanel | >=55.9999.61<56.0.27 | |
Cpanel Cpanel | >=57.9999.48<58.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10796 is classified as a medium severity vulnerability due to its impact on the security of log files.
To fix CVE-2016-10796, ensure that you update your cPanel to version 58.0.4 or later.
CVE-2016-10796 affects cPanel versions below 58.0.4, including versions in the ranges 11.51, 11.54, and 55.9999.
The main issue with CVE-2016-10796 is that it allows weak permissions on Apache HTTP Server log files, potentially exposing sensitive information.
While the best solution is to update cPanel, adjusting file permissions on the log files may temporarily mitigate the risk associated with CVE-2016-10796.