Parallels Plesk Panel for Linux 12.x & 11.x secret_key leak

Security annoucements of interest to the AtomiCorp community, such as vulnerabilities in third party applications.
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Parallels Plesk Panel for Linux 12.x & 11.x secret_key leak

Unread post by mikeshinn »

Parallels reports that there is a potential vulnerability in Parallels Plesk Panel for Linux 11, 11.5 and 12 preview that may allow an attacker to get access to the /etc/psa/private/secret_key file. This is a link to the official announcement from Parallels:

http://kb.parallels.com/121310

And a link to the mailing list post from Tim Rots who discovered this vulnerability:

http://seclists.org/fulldisclosure/2014/Apr/255

Atomic Secured Linux and Real Time Modsecurity rules customers with up to date rules are automatically protected from this vulnerability, if the Plesk Control Panel is being protected by either the T-WAF in ASL or a proxy running the Atomicorp Real Time rules. Make sure you have a local WAF setup for port 8443 and you'll be protected.

For ASL users, please see this documentation to configure ASL to protect your control panel if you have not configured your system to do this already:

https://www.atomicorp.com/wiki/index.php/ASL_WAF#local
Locked