CVE-2017-18451: Medium severity cpanel vulnerability
Published Aug 2, 2019
·Updated
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
Affected Software
5 affected components
Cpanel Cpanel>=56.0.1<56.0.49
Cpanel Cpanel>=58.0.3<58.0.49
Cpanel Cpanel>=60.0.3<60.0.43
Cpanel Cpanel>=62.0.1<62.0.24
Cpanel Cpanel>=64.0.0<64.0.21
Event History
Aug 2, 2019
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18451?
CVE-2017-18451 is classified as a medium severity vulnerability that allows unauthorized reading of user crontab files in specific cPanel versions.
2
How do I fix CVE-2017-18451?
To fix CVE-2017-18451, upgrade your cPanel to version 64.0.21 or later.
3
Which versions of cPanel are affected by CVE-2017-18451?
CVE-2017-18451 affects cPanel versions 56.0.1 to 56.0.49, 58.0.3 to 58.0.49, 60.0.3 to 60.0.43, 62.0.1 to 62.0.24, and 64.0.0 to 64.0.21.
4
What kind of attack does CVE-2017-18451 allow?
CVE-2017-18451 allows attackers to potentially read sensitive user crontab files during a brief period following a cPAddon upgrade.
5
Is there a patch for CVE-2017-18451?
Yes, the patch for CVE-2017-18451 is included in cPanel version 64.0.21 and later.