1
0
mirror of https://git.FreeBSD.org/ports.git synced 2024-11-19 00:13:33 +00:00
freebsd-ports/www/kanboard
Fernando Apesteguía ad5f302a49 www/kanboard: update to 1.2.30
ChangeLog: https://github.com/kanboard/kanboard/releases/tag/v1.2.30

 * CVE-2023-33956: Parameter based Indirect Object Referencing leading to private
   file exposure
 * CVE-2023-33968: Missing access control allows user to move and duplicate tasks
   to any project in the software
 * CVE-2023-33969: Stored XSS in the Task External Link Functionality
 * CVE-2023-33970: Missing access control in internal task links feature

 * Avoid PHP warning caused by session_regenerate_id()
 * Avoid CSS issue when upgrading to v1.2.29 without flushing user sessions

Reported by:	portscout
MFH:		2023Q2 (security release)
Security:	CVE-2023-33956 CVE-2023-33968 CVE-2023-33969 CVE-2023-33970
2023-06-06 14:02:07 +02:00
..
distinfo www/kanboard: update to 1.2.30 2023-06-06 14:02:07 +02:00
Makefile www/kanboard: update to 1.2.30 2023-06-06 14:02:07 +02:00
pkg-descr
pkg-plist www/kanboard: Update to 1.2.29 2023-05-31 08:34:41 +02:00