Source: sabnzbdplus Severity: grave Tags: security upstream fixed-upstream X-Debbugs-Cc: [email protected], [email protected]
Hi, two further vulnerabilities were discovered in sabnzbd that allow unauthenticated API access respectively remote code execution. Both issues are fixed in upstream release 5.1.3. No CVEs have been issued yet. * __wrapped__ dispatch bypass allows unauthenticated API access. https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-q326-jpxx-jmjc * PAR2 symlink bypass allows pickle remote code execution. https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-mjwj-v5mr-cmcg Upstream provides an overview of all the recent vulnerability at https://sabnzbd.org/wiki/extra/5.1-vulnerabilities.html I'll upload the new upstream release to unstable today, and intend to prepare patches for backports and older Debian releases as soon as possible.
pgpHxDAgVe6ir.pgp
Description: OpenPGP digital signature

