• Plesk Uservoice will be deprecated by October. Moving forward, all product feature requests and improvement suggestions will be managed through our new platform Plesk Productboard.
    To continue sharing your ideas and feedback, please visit features.plesk.com

Issue Important: Imunify auto installation and possible data leak

Well there are 2 issues here in general:

Installation possible by-passing Plesk (and Customers)​

I do understand when you have the Immunify extension activated/installed on purpose the extension party (CloudLinux) has the power to make changes to our system. The problem here is ofcourse Plesk gives full power to an extension supplier which makes major (unwanted) changes to servers which do not have the extension enabled.

This makes supplies-chain attacks very easy.

Downsizing the issue​

I see that Plesk and CloudLinux downsizing the problem. They totally ignored the above points. The facts is that we have seen servers where files are uploaded to CL servers EVEN without us having a license.

This might be a sign there is no open-culture about security in Plesk . F*ckups can be made (been there, done that). But get your act together apoligize and tell us what you gonna do to prevent these kind of incidents. Running a internet business is hard enought already without vendors causing havoc
 
Back
Top