Back to Security Advisories

Security Advisory: CloudLinux $HTTP_HOST Environment Injection

A vulnerability in CloudLinux LVE Manager allowed environment variable injection via the $HTTP_HOST header, potentially leading to unauthorized access to protected resources.

High
CloudLinux CloudLinux 7 CloudLinux 9

Affected Versions

7.4 and earlier

Patched Version

7.5

Default Update CMD

yum update -y

Fix Commands

CloudLinux 7

yum clean all
yum update cl-lve

CloudLinux 9

dnf clean metadata
dnf update cl-lve

A vulnerability in CloudLinux LVE Manager allowed environment variable injection via the $HTTP_HOST header, potentially leading to unauthorized access to protected resources.

Check your system for vulnerabilities

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Check Your System