[Tickets #14857] Re: Multiple XSS security vulnerabilities

[email protected]
Newsgroups gmane.comp.horde.bugs
Message-ID <[email protected]>
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: https://bugs.horde.org/ticket/14857
------------------------------------------------------------------------------
  Ticket             | 14857
  Updated By         | Michael Rubinsky <[email protected]>
  Summary            | Multiple XSS security vulnerabilities
  Queue              | Horde Groupware
  Version            | 5.2.22
  Type               | Bug
  State              | Unconfirmed
  Priority           | 3. High
  Milestone          |
  Patch              |
  Owners             |
------------------------------------------------------------------------------


Michael Rubinsky <[email protected]> (2018-09-24 17:49) wrote:

This is the first time that I'm seeing these, will investigate.

> Several security vulnerabilities were publicly disclosed.
>
> https://code610.blogspot.com/2017/11/rce-via-xss-horde-5219.html
>
> They are also known as CVE-2017-16906, CVE-2017-16907,  
> CVE-2017-16908 and CVE-2017-17781.
>
> Are you aware of these issues? The bug reporter claims that they are  
> still present in the latest stable release. If you have already  
> fixed them, I would appreciate more information about the concrete  
> fixes because Debian and other Linux distributions would like to fix  
> those issues.
>
> Thanks in advance
>
> Markus Koschany ([email protected])




-- 
bugs mailing list
Frequently Asked Questions: http://wiki.horde.org/FAQ
To unsubscribe, mail: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.