CVE-2017-18427: Low severity cpanel vulnerability
Published Aug 2, 2019
·Updated
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
Affected Software
6 affected components
Cpanel Cpanel>=55.9999.61<56.0.51
Cpanel Cpanel>=57.9999.48<58.0.52
Cpanel Cpanel>=59.9999.58<60.0.45
Cpanel Cpanel>=61.9999.55<62.0.27
Cpanel Cpanel>=63.9999.74<64.0.33
Cpanel Cpanel>=65.9999.38<66.0.2
Event History
Aug 2, 2019
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18427?
CVE-2017-18427 is considered a medium severity vulnerability due to the potential exposure of sensitive log files.
2
How do I fix CVE-2017-18427?
To fix CVE-2017-18427, update cPanel to version 66.0.2 or later.
3
What are the risks associated with CVE-2017-18427?
The risks associated with CVE-2017-18427 include unauthorized access to sensitive information in log files.
4
Which versions of cPanel are affected by CVE-2017-18427?
CVE-2017-18427 affects cPanel versions prior to 66.0.2, including 55.x, 57.x, 59.x, 61.x, 63.x, and 65.x.
5
Is there a workaround for CVE-2017-18427?
Currently, the recommended solution for CVE-2017-18427 is to upgrade to the latest version of cPanel.