CVE-2017-18388: Input Validation
Published Aug 2, 2019
·Updated
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
Affected Software
4 affected components
Cpanel Cpanel>=61.9999.55<62.0.35
Cpanel Cpanel>=63.9999.74<64.0.42
Cpanel Cpanel>=65.9999.38<66.0.34
Cpanel Cpanel>=67.9999.64<68.0.15
Event History
Aug 2, 2019
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18388?
CVE-2017-18388 has a severity rating that indicates it can lead to unsafe file operations due to improper umask settings.
2
How do I fix CVE-2017-18388?
To fix CVE-2017-18388, upgrade your cPanel installation to version 68.0.15 or later.
3
Which versions of cPanel are affected by CVE-2017-18388?
CVE-2017-18388 affects cPanel versions prior to 68.0.15, including 62.x, 63.x, 64.x, and 66.x.
4
What type of vulnerability is CVE-2017-18388?
CVE-2017-18388 is classified as a file operation vulnerability due to the lack of proper umask controls in Jailshell.
5
Is my system at risk if I use an unpatched version of cPanel related to CVE-2017-18388?
Yes, systems using unpatched versions of cPanel before 68.0.15 are at risk of unsafe file operations.