Skip to main content

CPANEL-53195: External requests trigger HTTP 500 via cPanel 404 safelock failure

Comments

3 comments

  • cPRex Jurassic Moderator

    Thanks for sharing this!

    0
  • Zoltan Egri | 1b.hu

    Thanks!

    Quick update: still reproducible on 136.0 build 38 — we upgraded from build 37 specifically to check, and the same webmaild.lock Permission denied error came back shortly after, followed by the 500.

    Worth noting the trigger is an unauthenticated external request for a missing static file, coming from distributed scanners. Any internet-facing cPanel server will see this traffic.

    Is there a target version for the fix, or is CPANEL-53195 still under investigation? And is a request-level block (we used a targeted ModSecurity rule) the recommended interim mitigation?

    Full write-up with logs and the workaround: https://1b.hu/blog/cpanel-hiba-okozta-a-rejtelyes-500-as-szerverhibakat

    0
  • cPRex Jurassic Moderator

    Yes - the request-level block is still the best plan at this time.

    No - I don't have a specific build targeted for this fix just yet.  I did add your blog notes to the case for the developers to review.

    Once I hear something on my end I'll be sure to post!

    0

Please sign in to leave a comment.