PatchSiren

cPanel CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review cPanel CVE published 2024-11-18

CVE-2024-52316

cPanel’s EasyApache 4 2024.11.20 release includes a security update for Tomcat 10.1 to address CVE-2024-52316. The supplied vendor advisory does not describe the underlying flaw, but it does confirm that affected cPanel/WHM environments using EasyApache 4 should be updated to the fixed package set.

LOW cPanel CVE published 2024-10-08

CVE-2024-9026

cPanel’s EasyApache 4 2024.10.2 release includes security updates for PHP 8.1, 8.2, and 8.3 that address CVE-2024-9026. The supplied vendor note does not describe the flaw’s technical behavior, impact, or severity, so defenders should treat this as an official PHP-package remediation notice tied to cPanel/WHM-managed EasyApache 4 builds.

HIGH cPanel CVE published 2024-10-07

CVE-2024-31449

cPanel’s EasyApache 4 2024.10.9 release includes a security update for Redis 6.2.16 that addresses CVE-2024-31449. The vendor advisory does not provide exploit details in the supplied source, but it clearly identifies Redis as the affected component and ties the fix to this CVE. The same release also mentions a second Redis-related CVE, CVE-2024-31228, which suggests the update should be treated as a secu [truncated]

Review cPanel CVE published 2024-08-26

CVE-2023-49582

cPanel’s EasyApache 4 2024.8.29 release includes updated packages and a security update to APR that addresses CVE-2023-49582. The vendor notice also mentions updated NodeJS 20 and NodeJS 22 packages. Based on the supplied source, the key defensive takeaway is to apply the EasyApache 4 update on systems that rely on cPanel/WHM-managed Apache components.

Review cPanel CVE published 2024-08-13

CVE-2024-39929

cPanel’s official guidance indicates that CVE-2024-39929 has a patch available for cpanel-exim. According to the vendor advisory published on 2024-08-13, the issue was fixed in cpanel-exim versions 4.96.2-3.cp108 and 4.97.1-3.cp118. If your environment uses cPanel/WHM with an older cpanel-exim build, it should be treated as needing update review.

MEDIUM cPanel CVE published 2017-03-03

CVE-2017-5616

CVE-2017-5616 is a cross-site scripting (XSS) issue in cPanel's cgiemail and cgiecho CGI programs. According to the NVD record and the cPanel vendor advisory, a remote attacker could inject arbitrary web script or HTML through the addendum parameter. The CVE was published on 2017-03-03, with public references including an oss-security mailing list post and the vendor disclosure.

MEDIUM cPanel CVE published 2017-03-03

CVE-2017-5615

CVE-2017-5615 is a medium-severity issue affecting cPanel's cgiemail and cgiecho utilities. According to the NVD record and vendor advisory references, a remote attacker could inject HTTP headers by placing a newline character in the redirect location. Because the attack requires user interaction and can alter how a browser or intermediary handles the response, it can be used to manipulate redirects or re [truncated]

MEDIUM cPanel CVE published 2017-03-03

CVE-2017-5614

CVE-2017-5614 is an open redirect vulnerability in cgiemail and cgiecho that can be abused to send users to attacker-controlled websites. The primary impact is phishing and trust abuse: a victim can be steered away from a legitimate cPanel-hosted page using the success or failure parameter. NVD rates the issue 6.1/Medium, reflecting network reachability, no privileges required, and user interaction.

HIGH cPanel CVE published 2017-03-03

CVE-2017-5613

CVE-2017-5613 is a format string vulnerability (CWE-134) affecting cPanel's cgiemail and cgiecho CGI programs. NVD describes the flaw as allowing arbitrary code execution via format string specifiers in a template file, and rates it CVSS 7.8 HIGH. The NVD record also shows the affected cpe entries for cpanel:cgiemail and cpanel:cgiecho.