First published: Fri Aug 02 2019(Updated: )
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=61.9999.55<62.0.35 | |
Cpanel Cpanel | >=63.9999.74<64.0.42 | |
Cpanel Cpanel | >=65.9999.38<66.0.34 | |
Cpanel Cpanel | >=67.9999.64<68.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18388 has a severity rating that indicates it can lead to unsafe file operations due to improper umask settings.
To fix CVE-2017-18388, upgrade your cPanel installation to version 68.0.15 or later.
CVE-2017-18388 affects cPanel versions prior to 68.0.15, including 62.x, 63.x, 64.x, and 66.x.
CVE-2017-18388 is classified as a file operation vulnerability due to the lack of proper umask controls in Jailshell.
Yes, systems using unpatched versions of cPanel before 68.0.15 are at risk of unsafe file operations.