Bug 1083948 (CVE-2018-7667) - VUL-1: CVE-2018-7667: adminer: SSRF via the server parameter
Summary: VUL-1: CVE-2018-7667: adminer: SSRF via the server parameter
Status: RESOLVED FIXED
Alias: CVE-2018-7667
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 42.3
Hardware: Other Other
: P4 - Low : Minor (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/201188/
Whiteboard:
Keywords:
Depends on: 1002214
Blocks:
  Show dependency treegraph
 
Reported: 2018-03-05 12:51 UTC by Johannes Segitz
Modified: 2018-03-15 02:08 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2018-03-05 12:51:10 UTC
CVE-2018-7667

Adminer through 4.3.1 has SSRF via the server parameter.

No maintainer, would you be willing to take this one?

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-7667
http://hyp3rlinx.altervista.org/advisories/ADMINER-UNAUTHENTICATED-SERVER-SIDE-REQUEST-FORGERY.txt
Comment 1 Jimmy Berry 2018-03-05 16:24:01 UTC
No patch referenced, but based on description 4.4.0 should be first fine release. Fine to update it to that?
Comment 2 Swamp Workflow Management 2018-03-05 17:30:09 UTC
This is an autogenerated message for OBS integration:
This bug (1083948) was mentioned in
https://build.opensuse.org/request/show/583083 42.3 / adminer
Comment 3 Johannes Segitz 2018-03-05 21:53:59 UTC
(In reply to Jimmy Berry from comment #1)
yes, that would be fine. Thanks
Comment 4 Andreas Stieger 2018-03-09 07:36:02 UTC
in maintenance queue
Comment 5 Andreas Stieger 2018-03-14 20:11:55 UTC
releasing
Comment 6 Swamp Workflow Management 2018-03-15 02:08:01 UTC
openSUSE-SU-2018:0680-1: An update that solves one vulnerability and has one errata is now available.

Category: security (moderate)
Bug References: 1002214,1083948
CVE References: CVE-2018-7667
Sources used:
openSUSE Leap 42.3 (src):    adminer-4.4.0-4.5.1