CVE-2018-20894: Infoleak
Published Aug 1, 2019
·Updated
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
Affected Software
2 affected components
Cpanel Cpanel>=71.9980.30<72.0.10
Cpanel Cpanel>=73.9980.0<74.0.0
Event History
Aug 1, 2019
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20894?
CVE-2018-20894 is categorized with a moderate severity level as it allows local users to access each other's web-site contents.
2
How do I fix CVE-2018-20894?
To fix CVE-2018-20894, upgrade cPanel to version 74.0.0 or later.
3
What are the affected versions for CVE-2018-20894?
CVE-2018-20894 affects cPanel versions from 71.9980.30 to 72.0.10 and versions from 73.9980.0 to 74.0.0.
4
Can CVE-2018-20894 be exploited remotely?
No, CVE-2018-20894 can only be exploited by local users who have access to the system.
5
What impact does CVE-2018-20894 have on user privacy?
CVE-2018-20894 potentially compromises user privacy by allowing unauthorized access to web-site contents stored in Git repositories.