Security Advisory and Release

English news about the ticket system and this board
Dont create your support topics here!
Forum rules
Dont create your support topics here!
Locked
root
Administrator
Posts: 4350
Joined: 18 Dec 2007, 12:23
Znuny Version: Znuny and Znuny LTS
Real Name: Roy Kaldung
Company: Znuny
Contact:

Security Advisory and Release

Post by root »

**[Security Advisory] Critical: Authentication bypass in the Generic Interface with HTTPBasicAuth SSO**

We have released a security advisory for a **critical** authentication bypass.

**Affected:** installations that use the `HTTPBasicAuth` authentication module for SSO **and** have the Generic Interface enabled. On these systems, a remote attacker can execute Generic Interface operations **without authentication**.

**Affected versions:** Znuny LTS 6.0, Znuny LTS 6.5, Znuny 7.3.

Full explanation: https://www.znuny.com/en/blog/znuny-sec ... uth-bypass
Release notes: https://www.znuny.org/en/releases
Znuny and Znuny LTS running on CentOS / RHEL / Debian / SLES / MySQL / PostgreSQL / Oracle / OpenLDAP / Active Directory / SSO

Use a test system - always.

Do you need professional services? Check out https://www.znuny.com/

Do you want to contribute or want to know where it goes ?
Locked