Lucene search

K
mageiaGentoo FoundationMGASA-2023-0352
HistoryDec 19, 2023 - 10:08 p.m.

Updated fusiondirectory packages fix security vulnerabilities

2023-12-1922:08:39
Gentoo Foundation
advisories.mageia.org
13
fusiondirectory session-handling xss cve-2022-36179 cve-2022-36180 unix

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.5

Confidence

High

EPSS

0.004

Percentile

73.5%

The updated packages fix security vulnerabilities: Fusiondirectory 1.3 suffers from Improper Session Handling. (CVE-2022-36179) Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug;={Injection], /fusiondirectory/index.php?signout=1&message;=[injection]&plug;=106. (CVE-2022-36180)

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.5

Confidence

High

EPSS

0.004

Percentile

73.5%