cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
NVD-CWE-noinfo
CVE-2019-14408
cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).
CVE-2019-14409
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
CVE-2019-14411
cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).
CVE-2019-14413
cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).
CVE-2019-14414
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
