CVE-2021-38586: Medium severity Cpanel Cpanel vulnerability
Published Aug 11, 2021
·Updated
In cPanel before 98.0.1, /scripts/cpanconfig performs unsafe operations on files (SEC-589).
Affected Software
3 affected components
Cpanel Cpanel>=11.94.0.0<11.94.0.13
Cpanel Cpanel>=11.96.0.0<11.96.0.13
Cpanel Cpanel>=11.98.0.0<11.98.0.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
cPanelto a version that resolves this vulnerability.Fixed in 98.0.1Patch SEC-589
Event History
Aug 11, 2021
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-38586.
2
What is the title of this vulnerability?
The title of this vulnerability is 'In cPanel before 98.0.1 /scripts/cpan_config performs unsafe operations on files (SEC-589).'
3
What is the severity of CVE-2021-38586?
The severity of CVE-2021-38586 is medium (4.4).
4
Which software versions are affected by this vulnerability?
The software versions affected by this vulnerability are cPanel versions 11.94.0.0 to 11.94.0.13, 11.96.0.0 to 11.96.0.13, and 11.98.0.0 to 11.98.0.1.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following link: https://docs.cpanel.net/changelogs/98-change-log