In Progress [CPANEL-27863] After update to WHM 80 cPanel installed Litespeed without asking

servio

Member
Jun 6, 2019
6
0
1
UK
cPanel Access Level
Root Administrator
Hello,

It is horrible!

I am using Cloudlinux + EA4 + Apache 2.4 + mod_lsapi and after latest WHM 80 update Litespeed was installed without asking me!

I never bought any LID for Litespeed, it is joke that someone can buy LID for my IP and cPanel will install Litespeed?

From logs:

/var/cpanel/updatelogs/update.1559798761.log

[2019-06-05 22:28:11 -0700] Processing: Checking and provisioning LiteSpeed if licensed
[2019-06-05 22:28:11 -0700] - Processing command `/usr/local/cpanel/scripts/litespeed-check --run`
[2019-06-05 22:28:12 -0700] [/usr/local/cpanel/scripts/litespeed-check] Serial Number is XXXX


root 14904 0.0 0.0 112708 988 pts/0 S+ 11:18 0:00 grep --color=auto litespeed
root 26512 0.0 0.0 84428 52640 ? S 02:07 0:05 litespeed (lshttpd - main)
nobody 26538 0.0 0.0 102316 52728 ? Sl 02:07 0:24 litespeed (lshttpd - #01)
nobody 26539 2.7 0.1 305804 102964 ? Sl 02:07 15:18 litespeed (lshttpd - #02)
nobody 26540 0.0 0.0 101348 52540 ? Sl 02:07 0:22 litespeed (lshttpd - #03)
 

cPanelLauren

Forums Analyst II
Staff member
Nov 14, 2017
8,126
667
263
Houston
cPanel Access Level
DataCenter Provider
Hello @servio

I know that if purchased through our store litespeed will be automatically installed but if you didn't purchase it, this shouldn't occur.
I think in this instance the ability to look at the affected system and obtain more information is warranted. Can you please open a ticket using the link in my signature? Once open please reply with the Ticket ID here so that we can update this thread with the resolution once the ticket is resolved.


Thanks!
 

servio

Member
Jun 6, 2019
6
0
1
UK
cPanel Access Level
Root Administrator
Ticket 12511195

However I don't know who bought it..

So If I buy Litespeed LID for another server from another company cPanel night cron will install Litespeed? It is scary..
 

cPanelLauren

Forums Analyst II
Staff member
Nov 14, 2017
8,126
667
263
Houston
cPanel Access Level
DataCenter Provider
Ticket 12511195

However I don't know who bought it..

So If I buy Litespeed LID for another server from another company cPanel night cron will install Litespeed? It is scary..
There are some prerequisites, it has to correlate to the cPanel License for that specific server since cPanel licenses are issued per IP address and you'd have to purchase it in the cPanel store.
 

servio

Member
Jun 6, 2019
6
0
1
UK
cPanel Access Level
Root Administrator
"There are some prerequisites"

No and your support on ticket confirmed that it is issue.

It should working only when bought via cPanel market from WHM interface, however now it working too if someone buy on your website directly :)
 

cPanelLauren

Forums Analyst II
Staff member
Nov 14, 2017
8,126
667
263
Houston
cPanel Access Level
DataCenter Provider
There are prerequisites it just looks like all potential circumstances weren't visited. In this case a user on your server purchased this for your IP address through the cPanel store (this matches the IP address criteria and the purchase of it through the cPanel store criteria) based on this it looks like they'll most likely need to enforce some further rules on this to ensure that the purchaser is the admin of the server.

Your ticket prompted a case CPANEL-27863 /scripts/litespeed-check during upcp allows someone to force install litespeed in some cases

I'll update here when there is more information available or any updates on this case.


Thanks!