The record
Written from the 1 report below. Nothing here is unsourced.
- cPanel has warned that a critical flaw in LiteSpeed Web Server Enterprise, affecting versions before 6.3.7, could let a low-privilege hosting account gain root access on a shared-hosting server.
- An attacker with one hosting account on such a server could use the flaw to bypass isolation controls like CageFS and access or alter other customers' sites and the server itself.
- Neither cPanel nor LiteSpeed has released details on how the flaw works, whether it has been exploited, a CVE identifier, or a workaround, and no matching CVE record existed as of September 15.
- Administrators must manually run the update command to install version 6.3.7, because the release may be delayed in reaching auto-update and was still not listed as stable on LiteSpeed's download page as of September 15.
- The flaw matters because shared hosting concentrates many customers' sites on one machine, and it is the third LiteSpeed flaw since May reported to give a hosting account root access on cPanel servers, after two actively exploited plugin flaws.
What to watch next
- Whether LiteSpeed and cPanel publish technical details, a CVE identifier, or confirmation of exploitation
- Whether 6.3.7 becomes the stable release and reaches auto-update
- Whether a matching fix appears for OpenLiteSpeed, which had no update as of September 15
Coverage1
1 report
English national1
All filed from India
Named United States · CageFS · CloudLinux · LiteSpeed · LiteSpeed Web Server Enterprise · cPanel
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
