CVE-2024-53679: Apache VCL: XSS vulnerability in User Lookup impacting user privileges

2025-03-24 Thread Josh Thompson
Affected versions: - Apache VCL 2.1 through 2.5.1 Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with sufficient rights to be able to view this part of the site can craft a URL or be

CVE-2024-53678: Apache VCL: SQL injection vulnerability in New Block Allocation form

2025-03-24 Thread Josh Thompson
Affected versions: - Apache VCL 2.2 through 2.5.1 Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitted when requesting a new Block Allocation such that a SELECT SQL statement is modi

[jira] [Commented] (VCL-1127) Make changes to handle Cygwin's change of sshd service name to cygsshd

2025-03-24 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/VCL-1127?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17937951#comment-17937951 ] ASF subversion and git services commented on VCL-1127: -- Commit c3a6c91