[Buildroot] [PATCH] python-web2py: security bump to version 2.14.6
Peter Korsgaard
peter at korsgaard.com
Wed Apr 26 07:11:10 UTC 2017
>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:
> CVE-2016-4806 - Web2py versions 2.14.5 and below was affected by Local File
> Inclusion vulnerability, which allows a malicious intended user to
> read/access web server sensitive files.
> CVE-2016-4807 - Web2py versions 2.14.5 and below was affected by Reflected
> XSS vulnerability, which allows an attacker to perform an XSS attack on
> logged in user (admin).
> CVE-2016-4808 - Web2py versions 2.14.5 and below was affected by CSRF (Cross
> Site Request Forgery) vulnerability, which allows an attacker to trick a
> logged in user to perform some unwanted actions i.e An attacker can trick an
> victim to disable the installed application just by sending a URL to victim.
> CVE-2016-10321 - web2py before 2.14.6 does not properly check if a host is
> denied before verifying passwords, allowing a remote attacker to perform
> brute-force attacks.
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
Committed, thanks.
--
Bye, Peter Korsgaard
More information about the buildroot
mailing list