CVE-2018-20952: Infoleak
Published Aug 1, 2019
·Updated
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
Affected Software
3 affected components
Cpanel Cpanel>=61.9999.55<62.0.39
Cpanel Cpanel>=65.9999.38<66.0.35
Cpanel Cpanel>=67.9999.64<68.0.27
Event History
Aug 1, 2019
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20952?
CVE-2018-20952 has a severity rating that indicates it could lead to unauthorized access to sensitive files due to world-readable permissions.
2
How do I fix CVE-2018-20952?
To fix CVE-2018-20952, upgrade to cPanel version 68.0.27 or later, which addresses the permissions issue.
3
What versions of cPanel are affected by CVE-2018-20952?
CVE-2018-20952 affects cPanel versions prior to 68.0.27, as well as specific versions in the 61.x, 62.x, and 66.x series.
4
What is the impact of CVE-2018-20952?
The impact of CVE-2018-20952 includes the potential exposure of sensitive information due to files being accessible to all users.
5
Is there a workaround for CVE-2018-20952?
While the recommended solution is to upgrade, a temporary workaround is to manually correct file permissions on affected systems.