From 79bfa002bf2599163ddaf7783fa7060ac0c6de8d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A9bastien=20DAVOULT?= Date: Mon, 15 Mar 2021 11:31:42 +0100 Subject: [PATCH] 5.3-11 --- appliance/eonweb.spec | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/appliance/eonweb.spec b/appliance/eonweb.spec index fea55ee..1c50412 100644 --- a/appliance/eonweb.spec +++ b/appliance/eonweb.spec @@ -1,7 +1,7 @@ Summary: EyesOfNetwork Web Interface Name: eonweb Version: 5.3 -Release: 10 +Release: 11 Source: https://github.com/EyesOfNetworkCommunity/%{name}/archive/%{version}-%{release}.tar.gz Group: Applications/System License: GPL @@ -79,8 +79,10 @@ rm -rf %{buildroot} %config(noreplace) %{_sysconfdir}/httpd/conf.d/%{name}.conf %changelog -* Mon Jan 11 2021 Oscar POELS - 5.3-11.eon -- fix security issue with sessions_id by renforcing generation to prevent force brut +* Mon Mar 15 2021 Oscar POELS - 5.3-11.eon +- fix security issue CVE-2021-27514 (sessions_id by renforcing generation to prevent force brut) #82 #87 +- fix security issue CVE-2021-27513 (admin_ITSM, allows remote authenticated users to upload arbitrary .xml.php) #87 +- fix regression in admin_bp #85 * Tue Dec 08 2020 Sebastien DAVOULT - 5.3-10.eon - fix issue when we trying to rename rules in Advance Notifier #81