Bug 32113 - kanboard new security issue CVE-2023-36813
Summary: kanboard new security issue CVE-2023-36813
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard: MGA8TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2023-07-17 21:54 CEST by David Walser
Modified: 2023-07-19 21:01 CEST (History)
0 users

See Also:
Source RPM: kanboard-1.0.8-6.mga9.src.rpm
CVE:
Status comment: Fixed upstream in 1.2.31


Attachments

Description David Walser 2023-07-17 21:54:32 CEST
Debian has issued an advisory on July 16:
https://www.debian.org/security/2023/dsa-5454

The issue is fixed upstream in 1.2.31:
https://github.com/kanboard/kanboard/security/advisories/GHSA-9gvq-78jp-jxcx

Mageia 8 is also affected.
David Walser 2023-07-17 21:54:51 CEST

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Fixed upstream in 1.2.31

Comment 1 Lewis Smith 2023-07-19 21:01:19 CEST
Little activity on this, various packagers, so assigning globally.

Assignee: bugsquad => pkg-bugs


Note You need to log in before you can comment on or make changes to this bug.