Apache HTTP Server
by CPanel
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10786 | Med | 0.42 | 6.5 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186). | ||
| CVE-2018-20885 | Med | 0.35 | 5.3 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416). | ||
| CVE-2016-10796 | Low | 0.21 | 3.3 | 0.00 | Aug 6, 2019 | cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130). | ||
| CVE-2017-18429 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291). | ||
| CVE-2017-18424 | Low | 0.21 | 3.3 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274). | ||
| CVE-2018-20932 | Low | 0.18 | 2.7 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406). | ||
| CVE-2017-18412 | Low | 0.16 | 2.5 | 0.00 | Aug 2, 2019 | cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296). |
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
- risk 0.35cvss 5.3epss 0.01
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
- risk 0.21cvss 3.3epss 0.00
cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
- risk 0.21cvss 3.3epss 0.00
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
- risk 0.18cvss 2.7epss 0.01
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
- risk 0.16cvss 2.5epss 0.00
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).