Вернуться к предупреждениям о безопасности

Security: CSF Security Release

Multiple vulnerabilities were found in the ConfigServer Firewall plugin.

High
CloudLinux cPanel CSF CentOS 7 CloudLinux 7 CloudLinux 8

Команда обновления по умолчанию

cd /usr/src && rm -f csf.tgz && wget https://download.configserver.com/csf.tgz && tar -xzf csf.tgz && cd csf && sh install.sh && csf -r

Команды исправления

EL7 (CentOS/CloudLinux 7)

sudo yum update

EL8+ (AlmaLinux/CloudLinux/Rocky)

sudo dnf update

Что это значит по лицензии SharedLicense

Your SharedLicense license itself is not affected — this is a change in cPanel & WHM software, not in licensing. Reinstall CSF from the latest ConfigServer package (csf.tgz) and run csf -r. Licenses keep working through updates; nothing needs re-issuing or re-activating.

Situation

Multiple vulnerabilities were found in the ConfigServer Firewall plugin.

Affected Product Versions

Product Affected Versions Patched Versions
CSF 16.20-1 and earlier 16.30-1

Impact

Exploiting the vulnerabilities could allow an attacker to gain root access.

Call to action

Update to the latest version of the ConfigServer Firewall plugin:

CentOS 7/CloudLinux 7

# yum clean all

# /scripts/update-packages

AlmaLinux/CloudLinux 8/9/10

# dnf clean metadata

# /scripts/update-packages

Ubuntu

# apt update

# /scripts/update-packages

Mitigation

The best mitigation for this problem is to update.

Проверьте систему на уязвимости

Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.

Проверьте свою систему