« Volver al listado

CVE-2017-18412

Estado: ModificadaBaja (2.5)—

cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-18412",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 1.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 2.5,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-08-02T14:15:13.630",
  "references": [
    {
      "url": "https://documentation.cpanel.net/display/CL/68+Change+Log",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://news.cpanel.com/cpanel-tsr-2017-0005-full-disclosure/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "nvd@nist.gov"
    },
    {
      "url": "https://documentation.cpanel.net/display/CL/68+Change+Log",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-532"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296)."
    },
    {
      "lang": "es",
      "value": "cPanel anterior al versión 67.9999.103, permite que los archivos de registro del Servidor HTTP de Apache sean legibles en todo el mundo debido al manejo inapropiado de un cambio de nombre de cuenta (SEC-296)."
    }
  ],
  "lastModified": "2026-06-17T01:12:48.177",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08B24A9B-F2D3-4282-9270-0A6E3166B726",
              "versionEndExcluding": "56.0.52",
              "versionStartIncluding": "55.9999.61"
            },
            {
              "criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C72F220-BEF2-41F6-8312-A5DE70D2E218",
              "versionEndExcluding": "60.0.48",
              "versionStartIncluding": "59.9999.58"
            },
            {
              "criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6F6E962-A1DA-4B7F-9A32-1182DAA065D5",
              "versionEndExcluding": "62.0.30",
              "versionStartIncluding": "61.9999.55"
            },
            {
              "criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "179399A2-B445-44BF-BB64-F212CB267EB0",
              "versionEndExcluding": "64.0.40",
              "versionStartIncluding": "64.0.0"
            },
            {
              "criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6FDB6E8-4C9D-47B4-90AD-6022D9DD5976",
              "versionEndExcluding": "66.0.23",
              "versionStartIncluding": "65.9999.38"
            },
            {
              "criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07B4EC93-FA39-4633-92FD-B7CA330D3F2D",
              "versionEndExcluding": "67.9999.103",
              "versionStartIncluding": "67.9999.64"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}