CVE-2018-20892: Medium severity cpanel vulnerability
Published Aug 1, 2019
·Updated
cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).
Affected Software
3 affected components
Cpanel Cpanel>=69.9999.122<70.0.53
Cpanel Cpanel>=71.9980.30<72.0.10
Cpanel Cpanel>=73.9980.0<74.0.0
Event History
Aug 1, 2019
CVE Published
via MITRE·01:09 PM
Data Sourced
via MITRE·01:09 PM
Description
Frequently Asked Questions
1
What versions of cPanel are affected by CVE-2018-20892?
CVE-2018-20892 affects cPanel versions prior to 74.0.0, specifically 69.9999.122 to 70.0.53, 71.9980.30 to 72.0.10, and 73.9980.0 to 74.0.0.
2
What type of vulnerability is CVE-2018-20892?
CVE-2018-20892 is a vulnerability that allows arbitrary zone file modifications due to incorrect handling of CAA records.
3
What is the potential impact of CVE-2018-20892?
The potential impact of CVE-2018-20892 includes unauthorized changes to DNS zone files, which can lead to DNS spoofing or hijacking.
4
How can I mitigate CVE-2018-20892?
To mitigate CVE-2018-20892, upgrade your cPanel installation to version 74.0.0 or later.
5
Is there a workaround for CVE-2018-20892 if I cannot upgrade?
There is no official workaround for CVE-2018-20892; the only solution is to upgrade to a patched version.