cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332).
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://documentation.cpanel.net/display/CL/68+Change+Log | release notes product |
https://news.cpanel.com/cpanel-tsr-2017-0006-full-disclosure/ | vendor advisory |