Situation
We have received notice that a critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server.
This could allow an attacker to access or alter other hosted websites and the server itself.
This issue can bypass expected account isolation controls, including CageFS, allowing a malicious website user to potentially escape its restricted environment and gain root-level access to the server.
Impact
Currently affected versions are LiteSpeed Web Server Enterprise versions prior to v6.3.7.
Call to Action
We strongly recommend upgrading all affected LiteSpeed Enterprise installations to
LiteSpeed Web Server Enterprise v6.3.7 or later.
LiteSpeed Web Server Enterprise v6.3.7 or later.
Please run the following command to perform an update to LiteSpeed v6.3.7:
# /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7
Comments
0 comments
Article is closed for comments.