A significant security vulnerability in LiteSpeed Web Server Enterprise has been identified, potentially allowing users with low-level access to gain root access on shared-hosting servers. This flaw, affecting versions prior to 6.3.7, was highlighted in an advisory by cPanel on September 14. Shared-hosting servers often run multiple customer websites on a single machine, meaning that an attacker could exploit this vulnerability to potentially access or modify other websites and the server itself. The advisory urges administrators to upgrade to LiteSpeed version 6.3.7, which was released on September 11. However, details about how the flaw operates remain undisclosed, and there is no CVE identifier or severity score associated with it. Whether the flaw has been exploited is also unknown. To update, administrators should manually install the new version using the command provided by both cPanel and LiteSpeed. This step is crucial because there may be delays before the release reaches the auto-update system. It is worth noting that this is the third reported flaw in LiteSpeed software on cPanel servers since May, although it is the first identified within the web server itself. Previous issues were found in the cPanel plugin and were being actively exploited at the time. Questions have been directed to LiteSpeed, cPanel, and CloudLinux for further clarification on the current flaw.
Critical Vulnerability in LiteSpeed Enterprise Risks Server Security
Critical LiteSpeed Enterprise vulnerability could allow low-privilege hosting account to achieve root on shared servers, risking cross-tenant compromise.
Executive Summary
A critical vulnerability in LiteSpeed Web Server Enterprise could allow low-privilege users to gain root access on shared servers, potentially compromising multiple sites. Administrators are urged to manually update to version 6.3.7 to mitigate this risk.
Actionable Insights
- Upgrade LiteSpeed Web Server to version 6.3.7 immediately.
- Manually check for server vulnerabilities due to delayed auto-updates.
- Monitor LiteSpeed's official communications for any further updates or patches.
Original source
thehackernews.com

