Security: CSF Security Release
Multiple vulnerabilities were found in the ConfigServer Firewall plugin.
CMD de actualización por defecto
cd /usr/src && rm -f csf.tgz && wget https://download.configserver.com/csf.tgz && tar -xzf csf.tgz && cd csf && sh install.sh && csf -r
Comandos de corrección
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Lo que esto significa bajo una licencia de SharedLicense
Your SharedLicense license itself is not affected — this is a change in cPanel & WHM software, not in licensing. Reinstall CSF from the latest ConfigServer package (csf.tgz) and run csf -r. Licenses keep working through updates; nothing needs re-issuing or re-activating.
Situation
Multiple vulnerabilities were found in the ConfigServer Firewall plugin.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| CSF | 16.20-1 and earlier | 16.30-1 |
Impact
Exploiting the vulnerabilities could allow an attacker to gain root access.
Call to action
Update to the latest version of the ConfigServer Firewall plugin:
CentOS 7/CloudLinux 7
# yum clean all
# /scripts/update-packages
AlmaLinux/CloudLinux 8/9/10
# dnf clean metadata
# /scripts/update-packages
Ubuntu
# apt update
# /scripts/update-packages
Mitigation
The best mitigation for this problem is to update.
Referencias
Comprueba tu sistema en busca de vulnerabilidades
Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.
Comprueba tu sistema