Описание
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the AuthType is set to anything but Basic, if the request contains an Authorization: Basic ... header, the password is not checked. This results in authentication bypass. Any configuration that allows an AuthType that is not Basic is affected. Version 2.4.13 fixes the issue.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 2.4.12-0ubuntu2 |
| esm-infra/bionic | released | 2.2.7-1ubuntu2.10+esm7 |
| esm-infra/focal | released | 2.3.1-9ubuntu1.9+esm1 |
| esm-infra/xenial | released | 2.1.3-4ubuntu0.11+esm9 |
| jammy | released | 2.4.1op1-1ubuntu4.12 |
| noble | released | 2.4.7-1.2ubuntu7.4 |
| plucky | released | 2.4.12-0ubuntu1.1 |
| upstream | released | 2.4.13 |
Показывать по
EPSS
8 High
CVSS3
Связанные уязвимости
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Basic`, if the request contains an `Authorization: Basic ...` header, the password is not checked. This results in authentication bypass. Any configuration that allows an `AuthType` that is not `Basic` is affected. Version 2.4.13 fixes the issue.
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Basic`, if the request contains an `Authorization: Basic ...` header, the password is not checked. This results in authentication bypass. Any configuration that allows an `AuthType` that is not `Basic` is affected. Version 2.4.13 fixes the issue.
cups has Authentication bypass with AuthType Negotiate
OpenPrinting CUPS is an open source printing system for Linux and othe ...
EPSS
8 High
CVSS3