Immediately patch CWP vulnerability that allows code execution as root on Linux servers
CWP, formerly known as CentOS Web Panel, is a free Linux control panel for managing dedicated web hosting servers and virtual private servers. The two vulnerabilities were discovered by Octagon Networks researcher Paulos Yibelo. They are tracked under the codes CVE-2021-45467 (file inclusion vulnerability) and CVE-2021-45466 (file write vulnerability) and can be chained to an RCE attack.
In short, when successfully exploiting these two vulnerabilities, hackers can bypass protections to gain access to restricted APIs without authentication.
This can be done by registering an API key via the include file vulnerability and creating a malicious authorized_keys file on the server using the file write vulnerability.
Although the vulnerability includes a patched file CVE-2021-45467, Octagon Network says it has found a way to bypass the patch and continue to exploit some of the servers. Security researchers at Octagon Network claim that when a sufficient number of Linux servers running CWP are patched, they will make their exploits (POCs) public.
According to the developers of CWP, their software supports the following operating systems: CentOS, Rocky Linux, Alma Linux and Oracle Linux.
While the CWP homepage claims that there are about 30,000 servers running CWP, news site BleepingComputer reports that nearly 80,000 servers running CWP are exposed to the Internet on BinaryEdge. More than 200,000 other CWP servers can be found on Shodan and Censys.
You should read it
- 12-year vulnerability in pkexec gives hackers root privileges on Linux
- How to install and use a vulnerability scanner in Linux
- The 5 best Linux server distributions
- 7 Enterprise Linux Server Distributions
- 12 best Linux server operating systems
- How to set up your own Git server on Linux
- How to manage remote Linux server using SSH
- New points in SQL Server 2017
May be interested
- Microsoft 'turns the wheel' to bring the old Network Connections settings back to Windows 11obviously the network connections setting is easier to use than the advanced network settings in windows 11's settings.
- Google will automatically upgrade free G Suite users to Paid Workspace from May 1, 2022in 2020, g suite was renamed google workspace, part of google's massive refactoring of its work apps. many different subscription plans have been changed, and now google wants to remove the remaining free version of g suite.
- MediaTek demonstrates Wi-Fi 7 2.4 times faster than Wi-Fi 6recently, mediatek demonstrated the hardware power of wi-fi 7 or wi-fi 802.11be in the presence of many customers and industry partners.
- YouTube Originals is shutting down soon, have you heard about the service?youtube originals is expected by google to become a counterweight to other very powerful platforms like netflix or amazon.
- Microsoft lists Windows 10 group policies that you should avoid touchingmicrosoft has just released a list of 25 policies that administrators should not touch on windows 10 and windows 11. the reason is because they do not provide optimal results or cause unexpected things.
- Detecting dangerous backdoors targeting both Windows, macOS and Linuxinternational cybersecurity researchers have just issued an urgent notice about a new type of cross-platform malware called 'sysjoker' that has been appearing all over the world.