CVE-2017-18423: Low severity cpanel vulnerability
Published Aug 2, 2019
·Updated
In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
Affected Software
6 affected components
Cpanel Cpanel>=56.0.1<56.0.51
Cpanel Cpanel>=58.0.3<58.0.52
Cpanel Cpanel>=60.0.3<60.0.45
Cpanel Cpanel>=62.0.1<62.0.27
Cpanel Cpanel>=64.0.0<64.0.33
Cpanel Cpanel>=66.0.1<66.0.2
Event History
Aug 2, 2019
CVE Published
via MITRE·03:38 PM
Data Sourced
via MITRE·03:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18423?
CVE-2017-18423 is considered a medium severity vulnerability due to the potential exposure of sensitive log files.
2
How do I fix CVE-2017-18423?
To address CVE-2017-18423, update your cPanel installation to version 66.0.2 or later.
3
What kind of data is exposed in CVE-2017-18423?
CVE-2017-18423 allows unauthorized access to domain log files which may contain sensitive user data.
4
What versions of cPanel are affected by CVE-2017-18423?
CVE-2017-18423 affects cPanel versions prior to 66.0.2.
5
Is CVE-2017-18423 specific to any operating system?
CVE-2017-18423 is not specific to any operating system; it affects cPanel installations regardless of the underlying OS.