CVE-2018-20890: Medium severity cpanel vulnerability
Published Aug 1, 2019
·Updated
cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).
Affected Software
3 affected components
Cpanel Cpanel>=69.9999.122<70.0.53
Cpanel Cpanel>=71.9980.30<72.0.10
Cpanel Cpanel>=73.9980.0<74.0.0
Event History
Aug 1, 2019
CVE Published
via MITRE·01:06 PM
Data Sourced
via MITRE·01:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20890?
CVE-2018-20890 is classified as a medium severity vulnerability due to its potential for arbitrary zone file modifications.
2
How do I fix CVE-2018-20890?
To fix CVE-2018-20890, upgrade your cPanel version to at least 74.0.0.
3
What types of software are affected by CVE-2018-20890?
CVE-2018-20890 affects cPanel versions prior to 74.0.0, specifically versions 69.9999.122 to 70.0.53, 71.9980.30 to 72.0.10, and 73.9980.0 to 74.0.0.
4
What is the nature of the vulnerability in CVE-2018-20890?
CVE-2018-20890 allows arbitrary modifications to zone files during record edits, potentially compromising DNS configurations.
5
When was CVE-2018-20890 disclosed?
CVE-2018-20890 was disclosed as part of a security report in 2018.