First published: Thu Aug 01 2019(Updated: )
cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=61.9999.55<62.0.39 | |
Cpanel Cpanel | >=65.9999.38<66.0.35 | |
Cpanel Cpanel | >=67.9999.64<68.0.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20936 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to sensitive configuration information.
To fix CVE-2018-20936, upgrade your cPanel installation to version 68.0.27 or later.
CVE-2018-20936 affects cPanel versions prior to 68.0.27, including versions 62.0.39 and 66.0.35.
CVE-2018-20936 facilitates attacks that may allow unauthorized users to read sensitive SRS secrets from the exim.conf file.
While upgrading is the primary fix for CVE-2018-20936, ensuring proper server configurations and access controls can help mitigate risks.