CVE-2022-48623: Critical severity cpanel vulnerability
Published Feb 13, 2024
·Updated
The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.
Affected Software
5 affected componentsFixes available
debian/libcpanel-json-xs-perl<=4.09-1, <=4.25-1
4.35-14.37-1
ubuntu/libcpanel-json-xs-perl<4.19-1ubuntu0.1
4.19-1ubuntu0.1
ubuntu/libcpanel-json-xs-perl<4.27-1ubuntu0.1
4.27-1ubuntu0.1
ubuntu/libcpanel-json-xs-perl<4.35-1
4.35-1
Rurban Cpanel\<4.33
Remediation
Event History
Feb 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
Description
Data Sourced
via NVD·05:15 AM
SeverityWeakness
Feb 28, 2024
Data Sourced
via Launchpad·03:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-48623?
CVE-2022-48623 has been classified as a high severity vulnerability due to the potential for information disclosure and denial of service.
2
How do I fix CVE-2022-48623?
To fix CVE-2022-48623, upgrade the Cpanel::JSON::XS package to version 4.33 or later for the affected systems.
3
What software is affected by CVE-2022-48623?
CVE-2022-48623 affects the Cpanel::JSON::XS package for Perl, specifically versions prior to 4.33.
4
What issues can CVE-2022-48623 cause?
CVE-2022-48623 can lead to sensitive information leakage and may also cause a denial of service.
5
Who is the vendor for the affected package in CVE-2022-48623?
The affected package Cpanel::JSON::XS is maintained by Rurban.