En

cPanel官网安全更新(2021-09-23)

来源:cPanel官网 发布日期:2021-09-23 阅读次数:1474 评论:0

基本信息

发布日期:2021-09-23(官方当地时间)

更新类型:安全更新

更新版本:99.9999.108

感知时间:2021-11-18 10:37:58

风险等级:未知

情报贡献:TSRC

更新标题

Change Log for 99.9999.108

更新详情

Fixed case COBRA-13435: Make AutoSSL not apply ancestor DCV substition for HTTP DCV.Fixed case CPANEL-38971: Create default SSL files using the default SSL key type.Fixed case CPANEL-39119: Fixed the use of the pkgacct command line options --skipmail and --skippublichtml when using with --incremental.Fixed case CPANEL-39150: Reseller accounts without domains no longer fail when self-changing passwords.Fixed case CPANEL-39172: Ensure cPanel initiated in progress backups are visible in the cPanel UI.Fixed case CPANEL-39173: `retrieve_customizations` WHMAPI call returns valid options instead of array length.Fixed case CPANEL-39224: Install crypt-perl earlier during install.[security] Fixed case SEC-592: Arbitrary code execution via install_locallib_loginprofile script.[security] Fixed case SEC-593: Cpanel::SecureDownload executes shell commands in an insecure manner.[security] Fixed case SEC-597, SEC-598, SEC-599, SEC-608: Stored-XSS Vulnerability in ModSecurity Rules Interface.[security] Fixed case SEC-600: Reflected-XSS Vulnerability in ModSecurity Vendors Interface.[security] Fixed case SEC-602: Self-XSS Vulnerability in WHM Change Hostname interface.[security] Fixed case SEC-603: Self-stored XSS Vulnerability in WHM Edit Reseller Nameservers and Privileges interface.[security] Fixed case SEC-604: Self-XSS Vulnerability in cPanel Default Address Interface.[security] Fixed case SEC-606: Passphrase submitted via GET request in scripts2/dogencrt.Fixed case CPANEL-38971: Use the configured default SSL/TLS key type when resetting the certificate for a service.Fixed case CPANEL-39014: Fix link for downloading archived raw access logs when using the cPanel service subdomain.Fixed case CPANEL-39050: Don't filter packages with extensions unless requested in the search params for whmapi1 matchpkgs.Fixed case CPANEL-39051: Failures to update authorized_keys via the UI will result in an appropriate error message appearing in the UI.Fixed case CPANEL-39081: Disallow entry of orphaned colons in Tweak Setting "Allow server-info and server-status".Fixed case CPANEL-39085: Fixes UI loading error on DynamicDNS page.Fixed case CPANEL-39086: Update cpanel-perl-532-quota to 1.8.2-2.cp1198.Fixed case CPANEL-39103: Update cpanel-php73 to 7.3.32-1.cp1198.Fixed case CPANEL-39149: Ensure main dovecot templates directory is not a broken symlink.Fixed case COBRA-13494: Replace expired hostname certificates.Fixed case CPANEL-38691: Ensure that /var/cpanel/webtemplates retains correct permissions on revert.Fixed case CPANEL-38704: Update cpanel-proftpd to 1.3.6c-3.cp1198.Fixed case CPANEL-38709: When transitioning from a trial retain automatically enabled analytics for root.Fixed case CPANEL-38710: cPanel users can add subdomains to addon domains via the Domains interface within cPanel.Fixed case CPANEL-38785: Fix PopBeforeSMTPSenders on CentOS 8 / AlmaLinux 8.Fixed case CPANEL-38807: Allow "Service Status" to detect Dovecot "imap" as up on Ubuntu.Fixed case CPANEL-38836: Fix backup of Exim configuration.Fixed case CPANEL-38892: UPCP will no longer hang if port 37 (outgoing) is blocked.Fixed case CPANEL-38901: Fix fail-back to installing the default EA4 profile when installing a custom EA4 profile fails.Fixed case CPANEL-38906: Fix Fileman::upload_files operapi-lint errors.Fixed case CPANEL-38920: Trailing colons (:) in server-info and server-status no longer allowed to be persisted.Fixed case CPANEL-38982: Fix non-printable characters in WHMAPI1 call update_sql_config.Fixed case CPANEL-39007: Update cpanel-mailman to 2.1.33-4.cp1198.Fixed case CPANEL-39016: Fixes a false warning message on the DNS Cluster page.Fixed case PH-16792: Ensure style images are rendered properly in WHM customization page when cPanel is using Jupiter theme.Fixed case CPANEL-38222: Fix sync'ing DNS Clusters with DNSSEC keys or invalid SOA records.Fixed case CPANEL-38849: Update cpanel-trigger-os-release to 1.2-1.cp1198.Fixed case CPANEL-38908: Have distro_changed_hook script restart cpsrvd.Fixed case COBRA-13471: Set OpenSSL verification to use “trusted-first” logic.Fixed case CPANEL-37823: Make cpsrvd ignore parent-node mail users on Webmail login.Fixed case CPANEL-37823: Fix cpsrvd’s redirection to a child node when hostname mismatches.Fixed case CPANEL-37946: Add --help to scripts/xfertool.Fixed case CPANEL-38391: Fix Fileman::upload_files documentation.Fixed case CPANEL-38605: WHM Link Server Nodes no longer fails on SSL for remote host not being verified.Fixed case CPANEL-38706: Fixes form validator for NAPTR dns record creation.Fixed case CPANEL-38794: Fix handling of inherited PHP version settings in the MultiPHP Manager.Fixed case CPANEL-38838: Lift quotas when installing a SSL for an account.Fixed case CPANEL-38847: Assure Ubuntu apt-cache gencaches and dpkg -irP calls are exclusive.Fixed case CPANEL-38862: Retry if download fails for database packages during fresh install.Fixed case CPANEL-38890: Optimze Ubuntu cpanel binaries for size.Fixed case BOO-1796: Ensure mytop is removed during upgrades to MariaDB 10.5 (v100).Fixed case COBRA-13085: Zone Editor: Add page sizes of 500 and 1,000; make 100 the default.Fixed case COBRA-13086: Zone Editor: Teach search filter to look at record data.Fixed case COBRA-13087: Zone Editor: Make new records always visible at the top.Fixed case COBRA-13437: Fix zone-file parse speed regression.Fixed case CPANEL-38313: Update Jupiter Tools page to show default group icon.Fixed case CPANEL-38352: Fix Modify Account errors from Account Enhancement being disabled.Fixed case CPANEL-38443: Improve WHM Marketplace handling of WordPress Toolkit.Fixed case CPANEL-38556: Cleandns process on Ubuntu 20.04 no longer fails due to a warning on a depricated setting.Fixed case CPANEL-38575: Make EMAILREPLYTO setting optional in Basic WHM Setup.Fixed case CPANEL-38617: Ensure main dovecot templates directory is a symlink to the versioned templates directory.Fixed case CPANEL-38637: Clarified limitations of Lets Encrypt on autoSSL page.Fixed case CPANEL-38651: Update the NVData default dir with the new user's home directory path.Fixed case CPANEL-38666: Fix the package "Change" link on the "Modify an Account" page after changing a username.Fixed case CPANEL-38668: Ensure wp-toolkit iContact notifications are able to be sent.Fixed case CPANEL-38675: Keep default package on servers updating to 100.Fixed case CPANEL-38689: Update cpanel-perl-532-testrail-api to 0.049-1.cp1198.Fixed case CPANEL-38718: Fix opposite check for exim binary.Fixed case CPANEL-38767: Fixes help description for TweakSettings gzip compression.Fixed case CPANEL-38775: Fix most warnings generated by WHM when logged in as a "reseller without domain".Fixed case CPANEL-38789: Updated build_locale_databases help message.Fixed case CPANEL-38791: Fix typographical errors in help message.Fixed case CPANEL-38792: Fixed misspelling in help/usage output of ftpupdate.Implemented case CPANEL-38697: Link to WordPress Toolkit on Main Menu in Jupiter.Implemented case CPANEL-38805: Jupiter Customization Feature Showcase.Fixed case BOO-1544: Fix issues with generating the Imunify360 dovecot PAM extension local template.Fixed case BOO-1648: Refactor Whostmgr::Mysql::Upgrade::Warnings.Fixed case BOO-1657: Provide support for PowerDNS 4.4.1.Fixed case BOO-1693: Remove dovecot's expire plugin and replace it with autoexpunge.Fixed case BOO-1696: Add MariaDB 10.6 initial support.Fixed case BOO-1699: Implement update_sql_config WHMAPI1 call.Fixed case BOO-1719: Update integration tests for newly supported versions of MariaDB.Fixed case BOO-1800: Fix javascript errors on the MySQL/MariaDB Upgrade UI.Fixed case COBRA-12971: Check for local tar errors before streaming over websocket.Fixed case COBRA-13032: Create api_token_get_details WHM API v1 call; alter unlink_server_node.Fixed case COBRA-13037: Add options on what to do with the API token when unlinking a server node.Fixed case COBRA-13045: Prevent distribution of IPv6 enabled accounts.Fixed case COBRA-13046: Prevent enabling IPv6 on distributed accounts.Fixed case COBRA-13055: Fix spurious warning in user-authenticated live transfers.Fixed case COBRA-13058: Remove broken link from hostname zone file in DNS Zone Manager.Fixed case COBRA-13063: Update MX records when updating child-node hostnames.Fixed case COBRA-13072: cPanel DNS zone mass edit: send file validation errors to cPanel callers.Fixed case COBRA-13073: Improve record name validation for A and AAAA records containing underscores.Fixed case COBRA-13092: Prevent enabling or disabling IPv6 on a child accounts.Fixed case COBRA-13100: Add child node info to listaccts output.Fixed case COBRA-13106: Add new 'Accounts Manager' interface to allow users to manage accounts that exist on the server.Fixed case COBRA-13109: Zone Manager: Fix implicit form submission.Fixed case COBRA-13110: Add character-string validation to HINFO, NAPTR, and TXT records.Fixed case COBRA-13322: Improve/tighten List Account’s description.Fixed case CPANEL-30985: Run update gatherer from cron instead of upcp.Fixed case CPANEL-36271: Clean up descriptions in Tweak Settings for jail /proc mounts.Fixed case CPANEL-36831: Reset for localhost IP as well as localhost when resetting the root MySQL/MariaDB password.Fixed case CPANEL-36975: Alter configure_firewall_for_cpanel so that it does not set up the cPanel-Firewall-1-INPUT chain when the 'skip_rules_added_by_configure_firewall_for_cpanel' Tweak Setting is enabled.Fixed case CPANEL-36994: Teach Proxy Subdomain utilities about ea-nginx.Fixed case CPANEL-37231: Remove newlines in link description.Fixed case CPANEL-37391: Improve the functionality of cPanel theme selection in the Firefox browser.Fixed case CPANEL-37483: Make API token restores accommodate existing tokens.Fixed case CPANEL-37510: Automatically add MAILTO=“” when creating crontab file for a user when adding entries to empty crontabs.Fixed case CPANEL-37526: Make local-authority check logic avoid CNAME records.Fixed case CPANEL-37533: Add "from" and Reply-To customization to iContact:.Fixed case CPANEL-37539: Download `EA4.list` and use `cPanelPublicPkgKey`.Fixed case CPANEL-37558: Fix Find TTL and singleton-RRtype JS problems in Zone Manager.Fixed case CPANEL-37621: Add libmysqlclient-dev for ubuntu installs.Fixed case CPANEL-37635: Skip /snap/ mounts on Ubuntu disk space checks.Fixed case CPANEL-37637: Add user crontab support on Ubuntu.Fixed case CPANEL-37642: Fix firewall logic on Ubuntu.Fixed case CPANEL-37666: Access init.d dir via /etc/init.d.Fixed case CPANEL-37691: disable fs.protected_regular by default.Fixed case CPANEL-37692: Move code using Cpanel::FindBin::findbin to Cpanel::Binaries:path:.Fixed case CPANEL-37750: Fix personalization_set()’s docs to be accurate.Fixed case CPANEL-37752: Fix /scripts/quotacheck to handle blank lines in quota files.Fixed case CPANEL-37774: Fix minor typo in cPanel Jupiter welcome modal.Fixed case CPANEL-37783: Update Cpanel::OS logic for distro compatibility.Fixed case CPANEL-37784: Fixes select all behavior on email accounts page.Fixed case CPANEL-37787: Clarify whether download during cPanel update is due to missing file or signature.Fixed case CPANEL-37801: Assure install/SUSetup happens prior to CPanelPost.Fixed case CPANEL-37829: Fix spurious my.cnf migration warnings.Fixed case CPANEL-37831: Adjust WHM 'Manage Wheel Group Users' for Ubuntu.Fixed case CPANEL-37832: Fix bugs in WHM >> Manage Plugins on Ubuntu.Fixed case CPANEL-37857: Make notify_expiring_certificates ignore child accounts.Fixed case CPANEL-37883: Add NGINX cache clearing button to cPanel.Fixed case CPANEL-37897: Fix dismiss feature of the cPanel welcome panel.Fixed case CPANEL-37925: Make package searches with listaccts case sensitive.Fixed case CPANEL-37926: Ensure SpamAssassin uses Pyzor when the software is available.Fixed case CPANEL-37938: Adjust is_supported_distro for fresh install.Fixed case CPANEL-37958: Stop providing /var/cpanel/sysinfo.config.Fixed case CPANEL-37972: Add task to update PUblicSuffix list during maintenance.Fixed case CPANEL-38008: Fix bug in Mailman managment interfaces on CentOS 8 & Ubuntu.Fixed case CPANEL-38011: Don't terminate processes listening on HTTP(s) ports over a reserved IP.Fixed case CPANEL-38022: Remove “scripts/safeup2date” and “scripts/checkup2date”.Fixed case CPANEL-38027: Ensure MultiPHP Manager sets the same PHP version for domains sharing the same document root..Fixed case CPANEL-38035: Add script to mass update email accounts quotas for a user.Fixed case CPANEL-38041: Teach iContact notification about default email account.Fixed case CPANEL-38060: Add new key to modifyacct API call.Fixed case CPANEL-38062: stop using 3rdparty/bin/python. Use /usr/bin/python2 instead.Fixed case CPANEL-38070: The rpmup script runs with or without the --verbose flag being set.Fixed case CPANEL-38071: Add new option to Modify An Account page in WHM.Fixed case CPANEL-38082: Adjust “scripts/disable_prelink” to work on Ubuntu systems.Fixed case CPANEL-38089: Improvements to cPanel Analytics.Fixed case CPANEL-38100: Make Perl forget file descriptors it gives to libcurl.Fixed case CPANEL-38103: Update cPanel Customization page to display information related to Jupiter customization.Fixed case CPANEL-38107: build_maxemails_config script now has --help support.Fixed case CPANEL-38110: cPanel PHP maximum execution time Tweak Setting now has a maximum value of 500, reflecting the effective maximum for this parameter.Fixed case CPANEL-38111: Fix async AskDnsAdmin client’s cancellation (prevent stalled AutoSSL).Fixed case CPANEL-38123: Update munin.conf when setting new hostname in WHM.Fixed case CPANEL-38158: Ensure cPanel scripts running under a jailed shell can determine the current operating system version.Fixed case CPANEL-38161: Abstract check_package_manager method.Fixed case CPANEL-38167: Fix/prevent bugs regarding duplicate hostname-history entries.Fixed case CPANEL-38173: Rename Version::Comapre::RPM to Package.Fixed case CPANEL-38193: Remame iContact Check::CpanelRPMs.Fixed case CPANEL-38195: Add the ability to create a reseller without a domain to WHM API 1 createacct.Fixed case CPANEL-38196: Ensure 'scripts/fix_reseller_acls' correctly saves stored ACL lists.Fixed case CPANEL-38212: Report proper system group name on Ubuntu in error messages to the “ticket_grant” WHM API1 call.Fixed case CPANEL-38220: Update php73 pkgs that previously had incorrect obsoletes set.Fixed case CPANEL-38227: Check for locally installed packages with Cpanel::Pkgr.Fixed case CPANEL-38228: Postgres login now accepts passwords created in the WMH Postgres Password tool that have backslashes (\).Fixed case CPANEL-38252: Update webmail navigation bar colors to match the Jupiter theme.Fixed case CPANEL-38266: Modify ownership of DKIM data directories for better compatibility with Ubuntu.Fixed case CPANEL-38274: use cPanel level lock waiting for rpm/dpkg commands.Fixed case CPANEL-38287: Address possible warnings related to forwarding mail for the “nobody” user on Ubuntu.Fixed case CPANEL-38292: MariaDB not starting after upgrade from MySQL.Fixed case CPANEL-38301: Prepare cPanel & WHM for WPTK Deluxe inclusion.Fixed case CPANEL-38335: Fix for bugs preventing analytics UI from being enabled.Fixed case CPANEL-38341: Ensure UI agreement with the result from invoking whmapi1 system_needs_reboot.Fixed case CPANEL-38342: Improve left nav search to use 'wordpress' and 'toolkit' to find WHM Marketplace.Fixed case CPANEL-38343: Fix detection of "reboot required" state on CloudLinux 6.Fixed case CPANEL-38364: Update the root user for the current hostname when calling set_local_mysql_root_password.Fixed case CPANEL-38366: Include “style” in the whmapi1 modifyacct output.Fixed case CPANEL-38377: Stop creating junk files in the account home directory when running a user backup with pkgacct.Fixed case CPANEL-38380: Ensure resetzone does not fail for invalid SOA record.Fixed case CPANEL-38388: Feature Showcase WordPress Toolkit Deluxe inclusion.Fixed case CPANEL-38393: Make get_available_applications API call include Terminal UI.Fixed case CPANEL-38404: Move the customizations template logic to a plugin to be reusable.Fixed case CPANEL-38407: Add Imunify keywords for WHM menu search.Fixed case CPANEL-38410: Fix for accounting.log generation.Fixed case CPANEL-38414: Make application manager aware of arbitrary non-versioned ruby.Fixed case CPANEL-38414: Make application manager aware of arbitrary dep bins.Fixed case CPANEL-38427: Expands feature description of the Mail module to end user.Fixed case CPANEL-38444: Set the server default theme to Jupiter for new installations.Fixed case CPANEL-38446: Update Trial banner with new user limit.Fixed case CPANEL-38468: Explicitly require nscd on all cPanel installs.Fixed case CPANEL-38473: Update cpanel-perl-532-mail-spamassassin to 3.004004-6.cp1198.Fixed case CPANEL-38475: Blacklisted IPs can be overridden by adding them via the Trusted SMTP IP section of the Exim Configuration Manager.Fixed case CPANEL-38476: Prevents reservation of server / shared IP address in Apache Reserved IP Editor.Fixed case CPANEL-38485: Stop downloading WordPress Toolkit Deluxe license check data for WPTK 5.6.2+.Fixed case CPANEL-38494: MariaDB will automatically restart after upgraded and after a server reboot.Fixed case CPANEL-38496: Fix the check for an outdated kernel in the Security Advisor.Fixed case CPANEL-38593: Hide account summary for accounts without domains.Fixed case CPANEL-38603: Improve discoverability of the default theme settings in WHM.Fixed case CPANEL-38620: Properly localize the numbers in CJT2’s page size selector.Fixed case CPANEL-38635: Update cpanel-clamav to 0.101.5-6.cp1198.Fixed case CPANEL-38648: Update the End User License Agreement and Pricing Agreement.Fixed case CPANEL-38674: Update the license change detector to use more reliable way to detect trial licenses.Implemented case CPANEL-37991: Apply customization stylesheet to users interface.Implemented case CPANEL-38036: Implement the ability to change the color of the graphics on the Solutions page in the Jupiter theme.Implemented case CPANEL-38153: Implement the ability to show a custom logo in the JupiterImplemented case CPANEL-38236: Improvement for license type and status detection.Implemented case CPANEL-38248: Implement the WHM API functions for update_customizations, retrieve_customizations, and delete_customizations.Implemented case CPANEL-38434: Add Customization support for resellers and add more validation.

软件描述

cPanel 是一套在网页寄存业中最享负盛名的商业软件,是基于于 Linux 和 BSD 系统及以 PHP 开发且性质为闭源软件;提供了足够强大和相当完整的主机管理功能,诸如:Webmail 及多种电邮协议、网页化 FTP 管理、SSH 连线、数据库管理系统、DNS 管理等远端网页式主机管理软件功能。

CVE编号

TSRC分析

暂无

业界资讯

暂无

评论

提交评论 您输入的评论有误,请重新输入