CVE-2017-18453: Input Validation
Published Aug 2, 2019
·Updated
cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
Affected Software
5 affected components
Cpanel Cpanel>=56.0.1<56.0.49
Cpanel Cpanel>=58.0.3<58.0.49
Cpanel Cpanel>=60.0.3<60.0.43
Cpanel Cpanel>=62.0.1<62.0.24
Cpanel Cpanel>=64.0.0<64.0.21
Event History
Aug 2, 2019
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18453?
CVE-2017-18453 has a medium severity rating due to its potential impact on user permissions.
2
How do I fix CVE-2017-18453?
To remediate CVE-2017-18453, upgrade to cPanel version 64.0.21 or later.
3
What systems are affected by CVE-2017-18453?
CVE-2017-18453 affects cPanel versions before 64.0.21, including various versions from 56.x to 64.x series.
4
What does CVE-2017-18453 vulnerability entail?
CVE-2017-18453 involves the inability of cPanel to preserve supplemental groups across account renames.
5
Is there a workaround for CVE-2017-18453?
There is no official workaround for CVE-2017-18453 other than applying the update to the latest version.