image credit: Freepik

Code execution bug patched in Imunify360 Linux server security suite

November 22, 2021

Via: ZDnet

A severe PHP deserialization vulnerability leading to code execution has been patched in Imunify360.

Discovered by Cisco Talos researcher Marcin ‘Icewall’ Noga, the vulnerability “could cause a deserialization condition with controllable data and then execute arbitrary code,” leaving web servers open to hijacking.

Tracked as CVE-2021-21956 and issued a CVSSv3 score of 8.2, the security flaw is present in CloudLinux’s Imunify360 versions 5.8 and 5.9. Imunify360 is a security suite for Linux web servers including patch management, domain blacklisting, and firewall features.

Read More on ZDnet