Plesk Obsidian 18.0.x security micro-updates released
A micro-update package containing various security improvements for the panel, web server and DNS components.
A micro-update package containing various security improvements for the panel, web server and DNS components.
Plesk micro-updates are configured to be applied automatically; a plan has been prepared for servers that are still using manual updates.
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.