Skocz do zawartości
  • Cześć!

    Witaj na forum RootNode - aby pisać u nas musisz się zarejestrować, a następnie zalogować. Posty pisane z kont niezarejestrowanych nie są widoczne publicznie.

Luka w Litespeed Enterprise


Rekomendowane odpowiedzi

Opublikowano

Hej, aktualizujcie swoje LSWS. Dziś do mnie, i pewnie do innych, przyszedł mail:

 

Cytat

 

URGENT — Security Advisory

A critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server.

This could allow an attacker to access or alter other hosted websites and the server itself.

This issue can bypass expected account isolation controls, including CageFS, allowing a malicious website user to potentially escape its restricted environment and gain root-level access to the server.

Affected: LiteSpeed Web Server Enterprise installations prior to v6.3.7
Status: Fix available
Severity: Critical

ACTION REQUIRED (immediately)

We strongly recommend upgrading all affected LiteSpeed Enterprise installations to:

LiteSpeed Web Server Enterprise 6.3.7 or later

The v6.3.7 update includes the following:

  • [Security] Enhance lscgid request authentication and validation.
  • [Security] Apply stronger validation of internal redirect URL.
  • [Security] Block setting of important internal-use environment variables from .htaccess.
  • [Feature] Enable post-quantum cryptography key exchange.
  • [Improvement] Add support for the MKCALENDAR request method.
  • [Bug fix] Address a race condition corner case for ModSecurity engine.
  • [Bug fix] Address an internal URL cache corner case.
  • [Bug fix] Improve Node.js process management to avoid lingering idle workers.
  • [Bug fix] Address HTTP/3 idle connection timeout issue.
  • [Bug fix] Address a namespace issue for natively configured vhost.
  • [Bug fix] Address a corner case in SHM locking.

 

Important Post-Upgrade Note

The stable v6.3.7 release includes an adjustment that permits tightly controlled, root-owned binaries to continue operating safely.

After upgrading, please review your server for unusual CGI activity or piped logging behavior and verify that server-level logging continues to function normally.

Please take action as soon as possible to secure your servers. If you need assistance with the upgrade or have concerns about possible exposure, our support team is ready to help.

Thank you for your immediate attention to this critical security update.

LiteSpeed Team

 

 

Jeśli chcesz dodać odpowiedź, zaloguj się lub zarejestruj nowe konto

Jedynie zarejestrowani użytkownicy mogą komentować zawartość tej strony.

Zarejestruj nowe konto

Załóż nowe konto. To bardzo proste!

Zarejestruj się

Zaloguj się

Posiadasz już konto? Zaloguj się poniżej.

Zaloguj się
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Korzystając z forum, wyrażasz zgodę na: Warunki użytkowania, Regulamin, Polityka prywatności.

Proszę nie wysyłać wiadomości na ten adres e-mail: [email protected]