Bug#1144839: sabnzbdplus: authentication bypass in the web interface
Jeroen Ploemen <[email protected]>
| Newsgroups | gmane.linux.debian.devel.bugs.rc |
|---|---|
| Message-ID | <[email protected]> |
Source: sabnzbdplus Severity: grave Tags: security patch upstream fixed-upstream X-Debbugs-Cc: [email protected], [email protected] Hi, a vulnerability was discovered in sabnzbdplus that allows any client with access to the password-protected web interface to obtain an authenticated session without knowing the username or password. Affected versions are all since 3.0.0 through 5.1.0; for Debian that translates to every release since bullseye. Fixed in upstream release 5.1.1, meanwhile uploaded to unstable as 5.1.1+dfsg-1. CVE: [not yet] Github: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-xrfq-jhgh-wqch Fix: https://github.com/sabnzbd/sabnzbd/commit/9a12300877a38becda23dada37fd4f9c488801a5 Patches (source debdiff) for the sabnzbdplus package in bookworm and trixie are attached, and published in the {bookworm,trixie}-security branches in the package's VCS on salsa. Both have been verified to build, install, run, and fix the security issue.
sabnzbdplus_3.7.1+dfsg-2+deb12u1.debdiff
(application/octet-stream, 4.6 KB) - not displayed
sabnzbdplus_4.5.0+dfsg-1+deb13u1.debdiff
(application/octet-stream, 6.6 KB) - not displayed
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEd8lhnEnWos3N8v+qQoMEoXSNzHoFAmqFgvYACgkQQoMEoXSN zHp2CxAAkqrq/ol/hdUKSFiorgFABxOBTbKCecxVhkxwg7u34AKlpGoU9/dJdo+0 RPYfiy7w93LFCqh0/z5x7ut+httiwnTSfPSYTipDLYQRo5xnPV4hz4iguActSQLx ajlcjKnSGT3bmjU6kWAJXWIeOPC82AQWeRgBg+z0iPUwey6vDfBCoubPtUpFHB8X 0hXv1JjtDR+k7E/J87//PzeQKIR/sf9bIErq0yX4t3OhMHzZNwYdaRDUYn4e9EgD 1Zv1fjrdUUbaD4THVUOfJoCHLtJYBFK6IJwC0rgzTgKic9j2iznGTQakZ7sZiofU wkFRmm9EDMNSBsGZ7aiWP1yUm+WhNcVYgQpQVvPzfeaI0Ftm0Tl/ELqJSOA0yZwE IWP/6YcRyRC6Bvp+IhixCJzAFC1ogUubJgEnmU7hJ0MOhop6l4GlFWF4WmWDekyM zHIDhkmS1vp1N869726kiOveIJgsAiELrYHdHid8e7NvBDy+nE1OEgqyubnda7Hx gu2s/74c4HG8QrQkdKkcOf4iwILA9Tnexs8kIWPN8OYTGPDnAN4YxNt1gD2UqOAa 4edS3CAXHkZSkglMj6Nw12yvTQZ4fGqXqsnKudtyzZYKnOM9/JI0C3SYSCZnInmD n6JITmSnYJ+u4GBEM614OZa4UcAAeBQfhIYteJlOWTPSsCdIZgo= =qCS7 -----END PGP SIGNATURE-----