REDHAT-BUG-2428098: High severity Plesk Plesk Obsidian vulnerability
Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the getpassword.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication, resulting in a persistent availability impact on the affected Plesk Obsidian instance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2428098?
The severity of REDHAT-BUG-2428098 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2428098?
To fix REDHAT-BUG-2428098, users should update their Plesk Obsidian to the latest version beyond 18.0.73.
What is the risk associated with REDHAT-BUG-2428098?
The risk associated with REDHAT-BUG-2428098 is rated at 33, indicating a significant impact on service availability.
Which versions of Plesk are affected by REDHAT-BUG-2428098?
Plesk Obsidian versions 8.0.1 through 18.0.73 are affected by REDHAT-BUG-2428098.
What kind of vulnerability is REDHAT-BUG-2428098?
REDHAT-BUG-2428098 is a Denial of Service (DoS) vulnerability affecting the get_password.php endpoint.