Security Leftovers
-
authentik: remote timing attack in MetricsView HTTP Basic Auth (CVE-2024-52307)
Authentik is a popular open source identity provider that can be self-hosted. SUSE IT is considering to use this software internally in the future and thus we have been asked to have a look at its security.
The Authentik version we examined was 2024.8.3. Beyond the finding in this report, we also discovered the possibility to access SSL private keys without authentication, but this was independently discovered and fixed in parallel by upstream before we had a chance to report it. The only CVE-worthy finding that was left is discussed in the next section. Some general insights into the security of Authentik are given in section 3).
-
LWN ☛ Security updates for Wednesday
Security updates have been issued by Debian (mpg123 and php8.2), Fedora (libsndfile, mingw-glib2, mingw-libsoup, mingw-python3, and qbittorrent), Oracle (pam:1.5.1 and perl-App-cpanminus), Red Hat (firefox, thunderbird, and webkit2gtk3), Slackware (mozilla), SUSE (firefox, rclone, tomcat, tomcat10, and xen), and Ubuntu (gh, libsoup2.4, libsoup3, pygments, TinyGLTF, and twisted).
-
PCLinuxOS/Mageia/Mandriva/OpenMandriva Family
-
PCLOS Official ☛ PCLinuxOS Recent Updates
thunderbird-128.5.0
chromium-browser-131.0.6778.85
basilisk-browser-2024.11.23
google-chrome-browser-131.0.6778.85
floorp-browser-11.21.0
opera-browser-114.0.5282.222
betterbird-115.18.0
microsoft-edge-browser-131.0.2903.70
bitwarden-2024.11.2
qalculate-qt-5.4.0
qalculate-gtk-5.4.0
nss-3.107
-