Date: Tue, 31 Jul 2012 12:22:16 +1200 From: Robbie MacKay <robbie@...ahidi.com> To: oss-security@...ts.openwall.com Cc: Heather Leson <HLeson@...ahidi.com> Subject: CVE request for Ushahidi The Ushahidi team have been notified of the following security vulnerabilities thanks to volunteers from OWASP Portland. These will be fixed in the upcoming 2.5 release. Could you please allocate CVEs for the following issues? * Multiple SQL injections (Reported by Timothy D. Morgan, Kees Cook, postmodern ) https://github.com/ushahidi/Ushahidi_Web/commit/fdb48d1 https://github.com/ushahidi/Ushahidi_Web/commit/6f6a919 https://github.com/ushahidi/Ushahidi_Web/commit/4764792 https://github.com/ushahidi/Ushahidi_Web/commit/d954093 https://github.com/ushahidi/Ushahidi_Web/commit/3301e48 https://github.com/ushahidi/Ushahidi_Web/commit/68d9916 https://github.com/ushahidi/Ushahidi_Web/commit/e0e2b66 https://github.com/ushahidi/Ushahidi_Web/commit/a11d43c https://github.com/ushahidi/Ushahidi_Web/commit/3f14fa0 * Missing authentication on comments, reports, email API calls (Reported by Kees Cook, Dennison Williams) https://github.com/ushahidi/Ushahidi_Web/commit/4c24325 https://github.com/ushahidi/Ushahidi_Web/commit/f67f4ad * User details exposed in comments API (Discovered by internal dev team) https://github.com/ushahidi/Ushahidi_Web/commit/529f353 * Admin user hijacking through the installer (Reported by Wil Clouser) https://github.com/ushahidi/Ushahidi_Web/commit/7892559 https://github.com/ushahidi/Ushahidi_Web/commit/fcdad03 * Stored XSS on member profile pages (Reported by Amy K. Farrell) https://github.com/ushahidi/Ushahidi_Web/commit/00eae4f Thanks in advance, Robbie Mackay Software Developer, External Projects Ushahidi Inc e: robbie@...ahidi.com skype: robbie.mackay
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.