Received: (at submit) by bugs.debian.org; 3 Feb 2024 20:12:57 +0000
X-Spam-Checker-Version: SpamAssassin 3.4.6-bugs.debian.org_2005_01_02
	(2021-04-09) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No,
 score=-9.9 required=4.0 tests=BAYES_00,FOURLA,FROMDEVELOPER,
	FVGT_m_MULTI_ODD,KHOP_HELO_FCRDNS,MD5_SHA1_SUM,RDNS_DYNAMIC,
	SPF_HELO_NONE,SPF_NONE,T_SCC_BODY_TEXT_LINE,XMAILER_REPORTBUG
	autolearn=ham autolearn_force=no
	version=3.4.6-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 27; hammy, 149; neutral, 51; spammy,
	1. spammytokens:0.945-+--H*r:bugs.debian.org
	hammytokens:0.000-+--H*F:U*carnil, 0.000-+--XDebbugsCc,
	0.000-+--X-Debbugs-Cc, 0.000-+--H*M:reportbug, 0.000-+--H*MI:reportbug
Return-path: <carnil@debian.org>
Received: from c-82-192-242-114.customer.ggaweb.ch ([82.192.242.114]:50862
 helo=eldamar.lan)
	by buxtehude.debian.org with esmtp (Exim 4.94.2)
	(envelope-from <carnil@debian.org>)
	id 1rWMNj-001AVt-3K
	for submit@bugs.debian.org; Sat, 03 Feb 2024 20:12:57 +0000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: ledgersmb: CVE-2024-23831
Message-ID: <170699117237.3456382.7218262254924227028.reportbug@eldamar.lan>
X-Mailer: reportbug 12.0.0
Date: Sat, 03 Feb 2024 21:12:52 +0100
Delivered-To: submit@bugs.debian.org

Source: ledgersmb
Version: 1.6.33+ds-2.1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
Control: found -1 1.6.9+ds-2+deb11u3 

Hi,

The following vulnerability was published for ledgersmb.

CVE-2024-23831[0]:
| LedgerSMB is a free web-based double-entry accounting system. When a
| LedgerSMB database administrator has an active session in /setup.pl,
| an attacker can trick the admin into clicking on a link which
| automatically submits a request to setup.pl without the admin's
| consent.  This request can be used to create a new user account with
| full application (/login.pl) privileges, leading to privilege
| escalation.  The vulnerability is patched in versions 1.10.30 and
| 1.11.9.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-23831
    https://www.cve.org/CVERecord?id=CVE-2024-23831
[1] https://github.com/ledgersmb/LedgerSMB/security/advisories/GHSA-98ff-f638-qxjm
[2] https://github.com/ledgersmb/LedgerSMB/commit/8c2ae5be68a782d62cb9c0e17c0127bf30ef4165

Regards,
Salvatore
