CVE-2018-20889: Infoleak
Published Aug 1, 2019
·Updated
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
Affected Software
3 affected components
Cpanel Cpanel>=69.9999.122<70.0.53
Cpanel Cpanel>=71.9980.30<72.0.10
Cpanel Cpanel>=73.9980.0<74.0.0
Event History
Aug 1, 2019
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20889?
CVE-2018-20889 has a moderate severity rating due to its potential to allow unauthorized file-read operations.
2
How do I fix CVE-2018-20889?
To fix CVE-2018-20889, upgrade to cPanel version 74.0.0 or later.
3
What versions of cPanel are affected by CVE-2018-20889?
CVE-2018-20889 affects cPanel versions prior to 74.0.0, specifically from versions 69.9999.122 to 70.0.53, and from 71.9980.30 to 72.0.10.
4
What type of vulnerability is CVE-2018-20889?
CVE-2018-20889 is a vulnerability that involves file-read operations via password file caching.
5
Is there a workaround for CVE-2018-20889?
No official workaround is provided for CVE-2018-20889; the recommended solution is to update to a patched version.