diff options
| author | Jochen Neumeister <joneum@FreeBSD.org> | 2026-09-22 04:24:54 +0000 |
|---|---|---|
| committer | Jochen Neumeister <joneum@FreeBSD.org> | 2026-09-22 04:25:33 +0000 |
| commit | 6ce5dd4a530fcbd05350e0f04883b7e8417aefa8 (patch) | |
| tree | e89de0ce010a066527b727065f1c307ee7018763 /security/libretls/ssh:/git@gitrepo.FreeBSD.org/(public-mirror) | |
| parent | 2855ba8e2b88984cd95bb096b2ef315b4c9c8e92 (diff) | |
Fixes an unauthenticated RCE in the worker API (GHSA-xcv3-gjwr-rwxw),
a WAF filename bypass via RFC 2231 encoding (GHSA-cvfx-2ffg-cqmj) and
three API permission flaws.
1.6.15 imports Configurator in the scheduler and the web UI, so add
common/gen to their PYTHONPATH. Run the Alembic migration before the
scheduler starts, upstream does this in its systemd wrapper, without
it the scheduler dies on the new is_draft column.
Ship a sample api.yml, the API refused to start without that file, and
bind it to localhost by default. Drop the ModSecurity directives from
the reverse proxy and web UI templates too, OpenResty has no such
module.
Changelog: https://github.com/bunkerity/bunkerweb/releases/tag/v1.6.15
Sponsored by: Netzkommune GmbH
Diffstat (limited to 'security/libretls/ssh:/git@gitrepo.FreeBSD.org/(public-mirror)')
0 files changed, 0 insertions, 0 deletions
