MGASA-2022-0090 - Updated webmin packages fix security vulnerability Publication date: 07 Mar 2022 URL: https://advisories.mageia.org/MGASA-2022-0090.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-0824, CVE-2022-0829 Less privileged Webmin users who do not have any File Manager module restrictions configured can access files with root privileges, if using the default Authentic theme (CVE-2022-0824, CVE-2022-0829). References: - https://bugs.mageia.org/show_bug.cgi?id=30116 - https://www.webmin.com/security.html - https://www.webmin.com/changes.html - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0824 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0829 SRPMS: - 8/core/webmin-1.990-1.mga8