LiteSpeed Enterprise flaw lets one hosting tenant gain root on a shared server
LiteSpeed disclosed that versions of its Enterprise web server before 6.3.7 contain a flaw that lets a low-privilege website user gain root access on the underlying server. On shared hosting, that means one tenant, reachable through a cheap plan or a stolen webmail login, can take over the whole machine and every other customer on it. Neither LiteSpeed nor cPanel has published how the flaw works, its severity, a CVE identifier, or whether it has been exploited, leaving defenders with little to hunt for. Because the update may be slow to arrive automatically, administrators are urged to install 6.3.7 manually. LiteSpeed's cPanel plugin had two similar exploited flaws earlier this year.
- Check
- Manually update LiteSpeed Enterprise to 6.3.7 now rather than waiting for auto-update, and on shared servers review tenant activity and privileges for signs of abuse given the missing technical details.
- Affected
- Shared-hosting providers and multi-tenant servers running LiteSpeed Enterprise before 6.3.7; a low-privilege website user can escalate to root and take over the entire server, exposing every other tenant's sites and data.
- Fix
- Install 6.3.7 manually across affected servers, isolate tenants, monitor for unexpected root processes and privilege escalation, rotate credentials on any suspected compromise, and treat shared hosting as one account from takeover.