Debian LTS: DLA-3486-1: ocsinventory-server update for php-cas
Summary
It now requires the baseURL of to-be-authenticated service to be
configured.
For ocsinventory-reports, this is configured with the variable
$cas_service_base_url in the file
/usr/share/ocsinventory-reports/backend/require/cas.config.php
Warning: regardless of this update, ocsreports-server should only be
used in secure and trusted environments.
For Debian 10 buster, this update is available through version
2.5+dfsg1-1+deb10u1.
We recommend that you upgrade your ocsinventory-server packages.
For the detailed security status of ocsinventory-server please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ocsinventory-server
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS