Debian Gosa vulnerabilities

6 known vulnerabilities affecting debian/gosa.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2019-11187CRITICALCVSS 9.8fixed in fusiondirectory 1.2.3-5 (bullseye)2019
CVE-2019-11187 [CRITICAL] CVE-2019-11187: fusiondirectory - Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 al... Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided. Scope: local bullseye: resolved (fixed in 1.2.3-5)
debian
CVE-2019-14466MEDIUMCVSS 6.5fixed in gosa 2.7.4+reloaded3-10 (bookworm)2019
CVE-2019-14466 [MEDIUM] CVE-2019-14466: gosa - The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP obj... The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a crafted cookie value, because unserialize is used to restore filter settings from a cookie. Scope: local bookworm: resolved (fixed i
debian
CVE-2018-1000528LOWCVSS 6.1fixed in gosa 2.7.4+reloaded3-5 (bookworm)2018
CVE-2018-1000528 [MEDIUM] CVE-2018-1000528: gosa - GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 cont... GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML. This attack appear to be exploitable via the victim must open a specially crafted web page. This vulnerability appears to hav
debian
CVE-2015-8771CRITICALCVSS 9.8fixed in gosa 2.7.4+reloaded2-6 (bookworm)2015
CVE-2015-8771 [CRITICAL] CVE-2015-8771: gosa - The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote... The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password. Scope: local bookworm: resolved (fixed in 2.7.4+reloaded2-6) bullseye: resolved (fixed in 2.7.4+reloaded2-6) forky: resolved (fixed in 2.7.4+reloaded2-6) sid: resolved (fixed in 2.7.4+reloaded2-6) trixie: resolved (fixed in
debian
CVE-2014-9760MEDIUMCVSS 6.1fixed in gosa 2.7.4+reloaded1-5 (bookworm)2014
CVE-2014-9760 [MEDIUM] CVE-2014-9760: gosa - Cross-site scripting (XSS) vulnerability in the displayLogin function in html/in... Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers to inject arbitrary web script or HTML via the username. Scope: local bookworm: resolved (fixed in 2.7.4+reloaded1-5) bullseye: resolved (fixed in 2.7.4+reloaded1-5) forky: resolved (fixed in 2.7.4+reloaded1-5) sid: resolved (fixed in 2.7.4+reloaded1-
debian
CVE-2007-0313MEDIUMCVSS 9.0fixed in gosa 2.5.8-1 (bookworm)2007
CVE-2007-0313 [CRITICAL] CVE-2007-0313: gosa - Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 a... Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 allows remote authenticated users to modify certain settings, including the admin password, via crafted POST requests. Scope: local bookworm: resolved (fixed in 2.5.8-1) bullseye: resolved (fixed in 2.5.8-1) forky: resolved (fixed in 2.5.8-1) sid: resolved (fixed in 2.5.8-1) trixie: resolv
debian