UbuntuUpdates.org

Bugs fixes in "gosa"

Origin Bug number Title Date fixed
CVE CVE-2019-14466 The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to per 2020-10-28
CVE CVE-2019-11187 Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing t 2020-10-28
CVE CVE-2018-1000528 GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password fo 2020-10-28
CVE CVE-2019-14466 The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to per 2020-10-28
CVE CVE-2019-11187 Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing t 2020-10-28
CVE CVE-2018-1000528 GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password fo 2020-10-28
Debian 940719 gosa: homepage field is outdated, server not found 2020-04-22
Debian 955314 gosa depends on php-recode which has been dropped 2020-04-22



About   -   Send Feedback to @ubuntu_updates