CVE-2020-10119: Critical severity cpanel vulnerability
Published Mar 17, 2020
·Updated
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).
Affected Software
1 affected component
Cpanel Cpanel<84.0.20
Event History
Mar 17, 2020
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10119?
The severity of CVE-2020-10119 is critical with a score of 9.8.
2
How can a demo account achieve remote code execution with CVE-2020-10119?
A demo account can achieve remote code execution through a cpsrvd rsync shell in cPanel versions prior to 84.0.20.
3
Which versions of cPanel are affected by CVE-2020-10119?
cPanel versions prior to 84.0.20 are affected by CVE-2020-10119.
4
Is there a fix available for CVE-2020-10119?
Yes, upgrading to cPanel version 84.0.20 or later fixes the vulnerability.
5
Where can I find more information about CVE-2020-10119?
You can find more information about CVE-2020-10119 in the cPanel 84 Change Log.