CVE-2017-18412: Low severity cpanel vulnerability
Published Aug 2, 2019
·Updated
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
Affected Software
6 affected components
Cpanel Cpanel>=55.9999.61<56.0.52
Cpanel Cpanel>=59.9999.58<60.0.48
Cpanel Cpanel>=61.9999.55<62.0.30
Cpanel Cpanel>=64.0.0<64.0.40
Cpanel Cpanel>=65.9999.38<66.0.23
Cpanel Cpanel>=67.9999.64<67.9999.103
Event History
Aug 2, 2019
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18412?
The severity of CVE-2017-18412 is considered to be medium due to the risk of exposing sensitive Apache HTTP Server log files.
2
How do I fix CVE-2017-18412?
To fix CVE-2017-18412, update cPanel to version 67.9999.103 or later.
3
Which versions of cPanel are affected by CVE-2017-18412?
CVE-2017-18412 affects cPanel versions prior to 67.9999.103, including multiple previous versions across the 55, 56, 59, 60, 61, 62, 64, and 66 releases.
4
What impact does CVE-2017-18412 have on security?
CVE-2017-18412 can potentially allow unauthorized users to read sensitive log files, posing a privacy risk for users.
5
Is a workaround available for CVE-2017-18412?
There are no official workarounds for CVE-2017-18412; upgrading to the fixed version is recommended.