CVE-2021-38588: High severity Cpanel Cpanel vulnerability
Published Aug 11, 2021
·Updated
In cPanel before 96.0.13, fixcpanelperl lacks verification of the integrity of downloads (SEC-587).
Affected Software
1 affected component
Cpanel Cpanel<96.0.13
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
cPanel fix_cpanel_perlto a version that resolves this vulnerability.Fixed in 96.0.13Patch SEC-587
Event History
Aug 11, 2021
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-38588?
CVE-2021-38588 is a vulnerability in cPanel before version 96.0.13 that allows unverified downloads in fix_cpanel_perl (SEC-587).
2
How severe is CVE-2021-38588?
CVE-2021-38588 has a severity score of 8.1 (high).
3
How does CVE-2021-38588 impact cPanel?
CVE-2021-38588 allows for unverified downloads in fix_cpanel_perl, which can compromise the integrity of the software.
4
How can I fix CVE-2021-38588?
To fix CVE-2021-38588, users should update cPanel to version 96.0.13 or later.
5
Where can I find more information about CVE-2021-38588?
You can find more information about CVE-2021-38588 in the cPanel change log at https://docs.cpanel.net/changelogs/96-change-log/