USN-4609-1
Dashboard / Vulnerabilities / USN-4609-1
USN-4609-1
Summary: gosa vulnerabilities
Details: Fabian Henneke discovered that GOsa incorrectly handled client cookies. An authenticated user could exploit this with a crafted cookie to perform file deletions in the context of the user account that runs the web server. (CVE-2019-14466) It was discovered that GOsa incorrectly handled user access control. A remote attacker could use this issue to log into any account with a username containing the word "success". (CVE-2019-11187) Fabian Henneke discovered that GOsa was vulnerable to cross-site scripting attacks via the change password form. A remote attacker could use this flaw to run arbitrary web scripts. (CVE-2018-1000528)
References: https://ubuntu.com/security/notices/USN-4609-1, https://ubuntu.com/security/CVE-2018-1000528, https://ubuntu.com/security/CVE-2019-11187, https://ubuntu.com/security/CVE-2019-14466
Affected packages
Package
Name: gosa
Purl: pkg:deb/ubuntu/[email protected]+reloaded2-9ubuntu1.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
