Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 9: 2024-0366 moderate: kanboard SQL injection threat

mageia
Calendar Grey November 22, 2024
Dist Mageia Esm H88
The recent kanboard package updates tackle critical security flaws, specifically highlighting SQL injection risks, announced on 22 Nov 2024.
In versions prior to 1.2.31 an authenticated user is able to perform a SQL injection, leading to a privilege escalation or loss of confidentiality

Summary

In versions prior to 1.2.31 an authenticated user is able to perform a SQL injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations the code improperly uses the PicoDB library to update/insert new information.

References

- https://bugs.mageia.org/show_bug.cgi?id=32113

- https://lists.debian.org/debian-security-announce/2023/msg00146.html

- https://www.cve.org/CVERecord?id=CVE-2023-36813

Resolution

SRPMS

- 9/core/kanboard-1.2.42-1.1.mga9

Publication date: 22 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0366.html
Type: security
CVE: CVE-2023-36813

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here