The GOsaFilterSettings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a crafted cookie value, because unserialize is used to restore filter settings from a cookie.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-desktop"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-dev"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-help-de"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-help-en"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-help-fr"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-help-nl"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-connectivity"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-dhcp"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-dhcp-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-dns"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-dns-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-fai"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-fai-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-gofax"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-gofon"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-goto"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-kolab"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-kolab-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-ldapmanager"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-mail"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-mit-krb5"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-mit-krb5-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-nagios"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-nagios-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-netatalk"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-opengroupware"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-openxchange"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-openxchange-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-opsi"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-phpgw"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-phpgw-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-phpscheduleit"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-phpscheduleit-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-pptp"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-pptp-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-pureftpd"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-pureftpd-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-rolemanagement"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-rsyslog"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-samba"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-scalix"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-squid"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-ssh"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-ssh-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-sudo"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-sudo-schema"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-systems"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-uw-imap"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-plugin-webdav"
},
{
"binary_version": "2.7.4+reloaded2-9ubuntu1.1",
"binary_name": "gosa-schema"
}
]
}
{
"binaries": [
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-desktop"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-dev"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-help-de"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-help-en"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-help-fr"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-help-nl"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-connectivity"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-dhcp"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-dhcp-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-dns"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-dns-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-gofax"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-gofon"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-goto"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-kolab"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-kolab-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-ldapmanager"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-mail"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-mit-krb5"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-mit-krb5-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-nagios"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-nagios-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-netatalk"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-opengroupware"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-openxchange"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-openxchange-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-phpgw"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-phpgw-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-phpscheduleit"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-phpscheduleit-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-pptp"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-pptp-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-pureftpd"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-pureftpd-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-rolemanagement"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-rsyslog"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-samba"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-scalix"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-squid"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-ssh"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-ssh-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-sudo"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-sudo-schema"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-systems"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-uw-imap"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-plugin-webdav"
},
{
"binary_version": "2.7.4+reloaded3-3",
"binary_name": "gosa-schema"
}
]
}