**[Security Advisory] Critical: Authentication bypass in the Generic Interface with HTTPBasicAuth SSO**
We have released a security advisory for a **critical** authentication bypass.
**Affected:** installations that use the `HTTPBasicAuth` authentication module for SSO **and** have the Generic Interface enabled. On these systems, a remote attacker can execute Generic Interface operations **without authentication**.
**Affected versions:** Znuny LTS 6.0, Znuny LTS 6.5, Znuny 7.3.
Full explanation: https://www.znuny.com/en/blog/znuny-sec ... uth-bypass
Release notes: https://www.znuny.org/en/releases
Security Advisory and Release
Forum rules
Dont create your support topics here!
Dont create your support topics here!
-
root
- Administrator
- Posts: 4350
- Joined: 18 Dec 2007, 12:23
- Znuny Version: Znuny and Znuny LTS
- Real Name: Roy Kaldung
- Company: Znuny
- Contact:
Security Advisory and Release
Znuny and Znuny LTS running on CentOS / RHEL / Debian / SLES / MySQL / PostgreSQL / Oracle / OpenLDAP / Active Directory / SSO
Use a test system - always.
Do you need professional services? Check out https://www.znuny.com/
Do you want to contribute or want to know where it goes ?
Use a test system - always.
Do you need professional services? Check out https://www.znuny.com/
Do you want to contribute or want to know where it goes ?