Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CA+O_gMzcN-qMjRPCwEyYUJb2+MKNARm2DJ3ZWeT886T-EVCXyg@mail.gmail.com>
Date: Tue, 31 Jul 2012 12:22:16 +1200
From: Robbie MacKay <robbie@...ahidi.com>
To: oss-security@...ts.openwall.com
Cc: Heather Leson <HLeson@...ahidi.com>
Subject: CVE request for Ushahidi

The Ushahidi team have been notified of the following security
vulnerabilities thanks to volunteers from OWASP Portland.
These will be fixed in the upcoming 2.5 release.
Could you please allocate CVEs for the following issues?

* Multiple SQL injections (Reported by Timothy D. Morgan, Kees Cook,
postmodern )
https://github.com/ushahidi/Ushahidi_Web/commit/fdb48d1
https://github.com/ushahidi/Ushahidi_Web/commit/6f6a919
https://github.com/ushahidi/Ushahidi_Web/commit/4764792
https://github.com/ushahidi/Ushahidi_Web/commit/d954093
https://github.com/ushahidi/Ushahidi_Web/commit/3301e48
https://github.com/ushahidi/Ushahidi_Web/commit/68d9916
https://github.com/ushahidi/Ushahidi_Web/commit/e0e2b66
https://github.com/ushahidi/Ushahidi_Web/commit/a11d43c
https://github.com/ushahidi/Ushahidi_Web/commit/3f14fa0

* Missing authentication on comments, reports, email API calls
(Reported by Kees
Cook, Dennison Williams)
https://github.com/ushahidi/Ushahidi_Web/commit/4c24325
https://github.com/ushahidi/Ushahidi_Web/commit/f67f4ad

* User details exposed in comments API (Discovered by internal dev team)
https://github.com/ushahidi/Ushahidi_Web/commit/529f353

* Admin user hijacking through the installer (Reported by Wil Clouser)
https://github.com/ushahidi/Ushahidi_Web/commit/7892559
https://github.com/ushahidi/Ushahidi_Web/commit/fcdad03

* Stored XSS on member profile pages (Reported by Amy K. Farrell)
https://github.com/ushahidi/Ushahidi_Web/commit/00eae4f

Thanks in advance,

Robbie Mackay

Software Developer, External Projects
Ushahidi Inc
e: robbie@...ahidi.com
skype: robbie.mackay

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.