Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 583676 - <net-p2p/syncthing-0.12.25: CSRF in REST API
Summary: <net-p2p/syncthing-0.12.25: CSRF in REST API
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL: https://github.com/syncthing/syncthin...
Whiteboard: ̃~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-05-21 15:36 UTC by Coacher
Modified: 2016-05-21 18:27 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Coacher 2016-05-21 15:36:02 UTC
Hello.

See ${URL} for the upstream bugreport.

Release notes for 0.12.x and 0.13.x series with this vulnerability fixed:
https://github.com/syncthing/syncthing/releases/tag/v0.12.25
https://github.com/syncthing/syncthing/releases/tag/v0.13.2

Fix for 0.12.x (included in 0.12.25): https://github.com/syncthing/syncthing/commit/4a228697cdc213b46ef3755c653bb7e9967248ae

Fix for 0.13.x (included in 0.13.2): https://github.com/syncthing/syncthing/commit/bf7fcc612d79133372b3d663fe0639a403e5467c
Comment 1 Coacher 2016-05-21 16:38:36 UTC
*** Bug 583666 has been marked as a duplicate of this bug. ***
Comment 2 Dirkjan Ochtman (RETIRED) gentoo-dev 2016-05-21 18:18:15 UTC
Bumped to 0.12.25, thanks for the quick report!
Comment 3 Dirkjan Ochtman (RETIRED) gentoo-dev 2016-05-21 18:18:36 UTC
(I also removed the vulnerable versions from the tree.)
Comment 4 Kristian Fiskerstrand (RETIRED) gentoo-dev 2016-05-21 18:27:33 UTC
(In reply to Dirkjan Ochtman from comment #3)
> (I also removed the vulnerable versions from the tree.)

Thanks, closing