Security: CSF Security Release
Multiple vulnerabilities were found in the ConfigServer Firewall plugin.
Default Update CMD
cd /usr/src && rm -f csf.tgz && wget https://download.configserver.com/csf.tgz && tar -xzf csf.tgz && cd csf && sh install.sh && csf -r
Fix Commands
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
What this means under a SharedLicense license
Your SharedLicense license itself is not affected — this is a change in cPanel & WHM software, not in licensing. Reinstall CSF from the latest ConfigServer package (csf.tgz) and run csf -r. Licenses keep working through updates; nothing needs re-issuing or re-activating.
Situation
Multiple vulnerabilities were found in the ConfigServer Firewall plugin.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| CSF | 16.20-1 and earlier | 16.30-1 |
Impact
Exploiting the vulnerabilities could allow an attacker to gain root access.
Call to action
Update to the latest version of the ConfigServer Firewall plugin:
CentOS 7/CloudLinux 7
# yum clean all
# /scripts/update-packages
AlmaLinux/CloudLinux 8/9/10
# dnf clean metadata
# /scripts/update-packages
Ubuntu
# apt update
# /scripts/update-packages
Mitigation
The best mitigation for this problem is to update.
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System