Mageia 2022-0090: webmin security update
Summary
Less privileged Webmin users who do not have any File Manager module
restrictions configured can access files with root privileges, if using
the default Authentic theme (CVE-2022-0824, CVE-2022-0829).
References
- https://bugs.mageia.org/show_bug.cgi?id=30116
- https://webmin.com/security/
- https://webmin.com/tags/webmin-changelog/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0824
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0829
Resolution
MGASA-2022-0090 - Updated webmin packages fix security vulnerability
SRPMS
- 8/core/webmin-1.990-1.mga8