Blesta version 6 has been released! Read More.
All posts
Security 2014-02-26 · Cody · 1 min read

Security Advisory – Various Staff Permission Issues

Security advisory: moderate staff permission flaws in Blesta 3.0.0-3.0.9 and 3.1.0-3.1.1 allow ACL bypass and delayed logout of inactive staff. Fixed in 3.0.10 and 3.1.2.

Affected Versions

Versions 3.0.0 through 3.0.9, and 3.1.0 through 3.1.1 are affected.

Description

Active and valid staff members may be able to access areas of the application without proper ACL permissions. Additionally, staff members may not be logged out immediately after being made inactive. These issues are classified as Moderate vulnerabilities. Patch release 3.0.10 and 3.1.2 correct these vulnerabilities.

Resolution

If you are running 3.0.x upgrade to version 3.0.10. If you are running 3.1.x upgrade to version 3.1.2.

Related tasks:

  1. CORE-1062
  2. CORE-1063
  3. CORE-1064

Credits

CORE-1062 was discovered by Nerijus Barauskas at NGnTC. CORE-1063 and CORE-1064 were discovered by the Blesta Development Team.

30-day free trial · No credit card · Your server

Read enough. Run it.

Everything on this blog ships in the box. Full product, free for 30 days, on your own server.

Download  6.0.0