*** This bug is a security vulnerability ***

Public security bug reported:

a vulnerability was discovered in sabnzbdplus that allows any client
with access to the password-protected web interface to obtain an
authenticated session without knowing the username or password.

Affected versions are 3.0.0 through 5.1.0; for Ubuntu that translates to
every release since focal/20.04. Fixed in upstream release 5.1.1,
meanwhile uploaded to Debian unstable as 5.1.1+dfsg-1.

CVE: [not yet]
Upstream advisory: 
https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-xrfq-jhgh-wqch
Upstream fix: 
https://github.com/sabnzbd/sabnzbd/commit/9a12300877a38becda23dada37fd4f9c488801a5
Debian bug: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144839

** Affects: sabnzbdplus (Ubuntu)
     Importance: Undecided
         Status: New

** Affects: sabnzbdplus (Debian)
     Importance: Unknown
         Status: Unknown

** Information type changed from Private Security to Public Security

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2164656

Title:
  web interface authentication bypass

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/sabnzbdplus/+bug/2164656/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to