*** This bug is a security vulnerability *** Public security bug reported:
a vulnerability was discovered in sabnzbdplus that allows any client with access to the password-protected web interface to obtain an authenticated session without knowing the username or password. Affected versions are 3.0.0 through 5.1.0; for Ubuntu that translates to every release since focal/20.04. Fixed in upstream release 5.1.1, meanwhile uploaded to Debian unstable as 5.1.1+dfsg-1. CVE: [not yet] Upstream advisory: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-xrfq-jhgh-wqch Upstream fix: https://github.com/sabnzbd/sabnzbd/commit/9a12300877a38becda23dada37fd4f9c488801a5 Debian bug: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144839 ** Affects: sabnzbdplus (Ubuntu) Importance: Undecided Status: New ** Affects: sabnzbdplus (Debian) Importance: Unknown Status: Unknown ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2164656 Title: web interface authentication bypass To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/sabnzbdplus/+bug/2164656/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
