Bug#1144839: sabnzbdplus: authentication bypass in the web interface

Jeroen Ploemen <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Source: sabnzbdplus
Severity: grave
Tags: security patch upstream fixed-upstream
X-Debbugs-Cc: [email protected], [email protected]

Hi,

a vulnerability was discovered in sabnzbdplus that allows any client
with access to the password-protected web interface to obtain an
authenticated session without knowing the username or password.

Affected versions are all since 3.0.0 through 5.1.0; for Debian that
translates to every release since bullseye. Fixed in upstream release
5.1.1, meanwhile uploaded to unstable as 5.1.1+dfsg-1.

CVE: [not yet]
Github: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-xrfq-jhgh-wqch
Fix: https://github.com/sabnzbd/sabnzbd/commit/9a12300877a38becda23dada37fd4f9c488801a5

Patches (source debdiff) for the sabnzbdplus package in bookworm and
trixie are attached, and published in the {bookworm,trixie}-security
branches in the package's VCS on salsa. Both have been verified to
build, install, run, and fix the security issue.
sabnzbdplus_3.7.1+dfsg-2+deb12u1.debdiff (application/octet-stream, 4.6 KB) - not displayed
sabnzbdplus_4.5.0+dfsg-1+deb13u1.debdiff (application/octet-stream, 6.6 KB) - not displayed
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEd8lhnEnWos3N8v+qQoMEoXSNzHoFAmqFgvYACgkQQoMEoXSN
zHp2CxAAkqrq/ol/hdUKSFiorgFABxOBTbKCecxVhkxwg7u34AKlpGoU9/dJdo+0
RPYfiy7w93LFCqh0/z5x7ut+httiwnTSfPSYTipDLYQRo5xnPV4hz4iguActSQLx
ajlcjKnSGT3bmjU6kWAJXWIeOPC82AQWeRgBg+z0iPUwey6vDfBCoubPtUpFHB8X
0hXv1JjtDR+k7E/J87//PzeQKIR/sf9bIErq0yX4t3OhMHzZNwYdaRDUYn4e9EgD
1Zv1fjrdUUbaD4THVUOfJoCHLtJYBFK6IJwC0rgzTgKic9j2iznGTQakZ7sZiofU
wkFRmm9EDMNSBsGZ7aiWP1yUm+WhNcVYgQpQVvPzfeaI0Ftm0Tl/ELqJSOA0yZwE
IWP/6YcRyRC6Bvp+IhixCJzAFC1ogUubJgEnmU7hJ0MOhop6l4GlFWF4WmWDekyM
zHIDhkmS1vp1N869726kiOveIJgsAiELrYHdHid8e7NvBDy+nE1OEgqyubnda7Hx
gu2s/74c4HG8QrQkdKkcOf4iwILA9Tnexs8kIWPN8OYTGPDnAN4YxNt1gD2UqOAa
4edS3CAXHkZSkglMj6Nw12yvTQZ4fGqXqsnKudtyzZYKnOM9/JI0C3SYSCZnInmD
n6JITmSnYJ+u4GBEM614OZa4UcAAeBQfhIYteJlOWTPSsCdIZgo=
=qCS7
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.