New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
cPanel LiteSpeed Web Server Vulnerability
cPanel has issued an urgent security advisory warning that a critical vulnerability in LiteSpeed Web Server Enterprise could allow a low-privileged shared-hosting user to gain root-level access to an affected server. Administrators are urged to upgrade LiteSpeed Enterprise to version 6.3.7 or later immediately.
The flaw affects LiteSpeed Web Server Enterprise versions earlier than 6.3.7. It is particularly serious for shared-hosting environments, where many separate customer websites and user accounts run on the same physical or virtual server.
https://cybersecuritynews.com/cpanel-litespeed-web-server-vulnerability/

Comments
LOL
.-. F*ck
This is pretty concerning as someone who uses OpenLiteSpeed. I asked LS yesterday if this affects OLS and no reply after 24 hours. I think they are leaving OLS unpatched so the root cause of the vulnerability isn't publicized yet, since OLS is open source. Terrifying from a company like them if so.
I've debated for a long time kicking back to Apache, maybe it's a good idea.
I moved couple sites to OLS not even a week ago and now it's not even clear if it's vulnerable or not. Their repos are currently not offering update 🤷