Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
Try EnsoVPN - Reliable VPN - 1-Day Free Trial
K.N Cloud — High-Performance KVM VPS in Miami,Frankfurt and Amsterdam
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Try EnsoVPN - Fast & Private VPN - 1-Day Free Trial
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

HestiaCP 1.9.7 with security updates released

niceboyniceboy Veteran
edited July 23 in News

Open source hosting control panel HestiaCP 1.9.7 with security updates released

Website : https://www.hestiacp.com

Support forum : https://forum.hestiacp.com

Github : https://github.com/hestiacp/hestiacp

Version name changes

Due to the implementation for building ARM64 packages on X86-64 hardware the versions of hestia-nginx / hestia-php has been changed the format used for 1.10 and forward.

hestia-nginx-x.y.z-revision-os+release_architecture.deb
hestia-php-x.y.z-revision-os+release_architecture.deb

It has no effect on the working. Both "hestia" package and "hestia-web-terminal" will follow in the future.
Security

Unauthenticated Remote Code Execution via Session Deserialisation Mismatch in Web Terminal (GHSA-gh6f-9gpr-x9m2)
IP Address Spoofing via CF-Connecting-IP Header (GHSA-73p3-rqpv-59wx)
Cross-site Scripting (XSS) in Hestia Control Panel (GHSA-fg7j-gpvw-2m73)
Client to Root RCE via Newline Injection in v-add-cron-job and Eval Stdout Poisoning in parse_object_kv_list (GHSA-5fpv-c8rg-x6r3)
Systematic Second-Order Command Injection in Queue System Leading to Root RCE (GHSA-47mf-74xr-f8x9)
Root RCE via double eval() on user-controlled config data in parse_object_kv_list() (func/main.sh) (GHSA-w3mx-xq85-8qqc)
Low-privilege to root command execution via unescaped web.conf path fields evaluated by v-search-user-object (GHSA-cr7q-frhq-xw4v)
HestiaCP 1.9.6 — SQL Injection in Database Password (CWE-89) (GHSA-8w7m-g9c2-9q9p)
HestiaCP <= 1.9.6 Authenticated Admin Takeover (GHSA-fcq6-p8cj-xx3c)

Features

Add: JSON files can now be edited directly in the File Manager (#5342)

Bug fixes

Fix: Add validation for backup fields in v-schedule-user-restore (#5510)
Improve security by removing eval from search utilities (#5509)
Bump file manager to version 7.14.4 (#5508)
Secure database user creation / password change to prevent SQL injection (#5511)
Fix typo in $KEEP_MONTHLY on v-backup-user-restic (#5409)
Allow installation to continue when netplan config is missing (#5406)
Fix missing HESTIA variable by sourcing hestia.conf (#5433)
Check SFTP jail status before add/delete user jail operations (#5420)
Fix incorrect comment in web/add/mail/index.php (#5428)
Fix private key detection not being propagated to sftpc() (#5426)
Make v-extract-fs-archive fully non-interactive during extraction (#5436)
Fix if statement in installer (#5440)
Docs: Add mail cleanup guidance (#5371)
Bump Roundcube to version 1.6.17 (#5492)
Thanked by 3Falzo forest amj

Comments

  • LeviLevi Veteran

    holy fck!! Those are tight vulns!

  • forestforest Member

    Root RCE via double eval() on user-controlled config data in parse_object_kv_list() (func/main.sh) (GHSA-w3mx-xq85-8qqc)

    What the fuck lmao

    Thanked by 1darkimmortal
  • FrobsyFrobsy Member

    does it support openlitespeed?

  • rpqurpqu Member

    @forest said:

    Root RCE via double eval() on user-controlled config data in parse_object_kv_list() (func/main.sh) (GHSA-w3mx-xq85-8qqc)

    What the fuck lmao

    Probably caught by Kimi

  • niznetniznet Member

    @Frobsy said:
    does it support openlitespeed?

    Nope. Nginx & Nginx+Apache only. I don't remember whether it can apache only...

    Thanked by 1Frobsy
  • niceboyniceboy Veteran

    @niznet said:

    @Frobsy said:
    does it support openlitespeed?

    Nope. Nginx & Nginx+Apache only. I don't remember whether it can apache only...

    Its Nginx & Nginx+Apache only. As of now, Nothing else including apache only...

Sign In or Register to comment.