Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian 10: DLA-3486-1 Critical Update: Ocsinventory-Server PHP-Cas

debian lts
Calendar Grey July 8, 2023
Dist Debian Esm H88
Ubuntu LTS Notice ULA-5634-2 amends ocsinventory-server to address API modifications in php-cas, improving both security measures and operational capabilities.
The source package ocsinventory-server, a Hardware and software inventory tool has been updated to address the API change in php-cas due to CVE-2022-39369, see DLA 3485-1 for detai...

Summary

It now requires the baseURL of to-be-authenticated service to be
configured.

For ocsinventory-reports, this is configured with the variable
$cas_service_base_url in the file
/usr/share/ocsinventory-reports/backend/require/cas.config.php

Warning: regardless of this update, ocsreports-server should only be
used in secure and trusted environments.


For Debian 10 buster, this update is available through version
2.5+dfsg1-1+deb10u1.

We recommend that you upgrade your ocsinventory-server packages.

For the detailed security status of ocsinventory-server please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ocsinventory-server

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: ocsinventory-server
Version: 2.5+dfsg1-1+deb10u1
CVE ID: n/a
Debian Bug:

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here