Dear Valued Customer,
We would like to inform you of an important security update affecting the ConfigServer Firewall (CSF) plugin used on some Linux hosting and server (VPS and Dedicated) environments.
Summary
A recently disclosed security issue has been identified in older versions of ConfigServer Firewall (CSF). According to the vendor, multiple vulnerabilities may allow an attacker to escalate privileges and potentially gain root-level access to an affected server.
Affected Versions
Vulnerable: CSF 16.20-1 and earlier
Patched: CSF 16.30-1 and later
Potential Impact
Successful exploitation of these vulnerabilities could allow unauthorized users to gain elevated privileges on affected systems, potentially compromising server security.
Recommended Action
Customers managing their own servers should update CSF to the latest available version immediately.
CentOS 7/CloudLinux 7
yum clean all
/scripts/update-packages
AlmaLinux/CloudLinux 8/9/10
dnf clean metadata
/scripts/update-packages
Ubuntu
apt update
/scripts/update-packages
Ref :
https://support.cpanel.net/hc/en-us/articles/42503837957015-Security-CSF-Security-Release
Please contact our Support team if you have any questions.