CVE-2017-18422: Low severity cpanel vulnerability
Published Aug 2, 2019
·Updated
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
Affected Software
6 affected components
Cpanel Cpanel>=56.0.1<56.0.51
Cpanel Cpanel>=58.0.3<58.0.52
Cpanel Cpanel>=60.0.3<60.0.45
Cpanel Cpanel>=62.0.1<62.0.27
Cpanel Cpanel>=64.0.0<64.0.33
Cpanel Cpanel>=66.0.1<66.0.2
Event History
Aug 2, 2019
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18422?
CVE-2017-18422 is categorized as a security vulnerability due to weak ownership and permissions settings.
2
How do I fix CVE-2017-18422?
To fix CVE-2017-18422, upgrade cPanel to version 66.0.2 or later.
3
What versions of cPanel are affected by CVE-2017-18422?
CVE-2017-18422 affects cPanel versions prior to 66.0.2, including 56.x, 58.x, 60.x, 62.x, and 64.x.
4
What impact does CVE-2017-18422 have on my server?
CVE-2017-18422 could potentially allow unauthorized access due to weak file permissions.
5
Is there a workaround for CVE-2017-18422?
There is no specific workaround for CVE-2017-18422; the best solution is to update to the latest version of cPanel.