URGENT — Security Advisory
Following yesterday’s security advisory, LiteSpeed has released an additional update addressing another corner case in internal redirect URL validation.
Because the original vulnerability could allow a malicious website user to bypass expected account-isolation controls, including CageFS, we strongly recommend that all customers update again to the latest available LiteSpeed Web Server Enterprise release.
Affected: LiteSpeed Web Server Enterprise installations not running the latest available release
Status: Additional security fix available
Action required: Update immediately
ACTION REQUIRED (immediately)
Please upgrade LiteSpeed Web Server Enterprise to the latest available version.
This update (v6.3.7 build 1) includes the following additional security fix:
[Security] Address another corner case in internal redirect URL validation.
Even if you updated following yesterday’s advisory, please apply this latest update to ensure your server includes the additional validation improvement.
After upgrading, please review your server for unusual CGI activity or piped logging behavior and verify that server-level logging continues to function normally.
If you need assistance with the upgrade or have concerns about possible exposure, our support team is ready to help.
Thank you for your immediate attention to this security update.
LiteSpeed Team