Forums

×

Warning

JUser: :_load: Unable to load user with ID: 348281
Medium
Offline
Resolved
2 votes
It looks like there is a critical vulnerability in the Web Server app (Apache/httpd) and the Webconfig. More information can be found at https://nvd.nist.gov/vuln/detail/CVE-2023-25690. We desperately need updated httpd and webconfig-httpd packages from Clearcenter for ClearOS to remain safe to use. Please, Clearcenter?
Monday, April 10 2023, 09:39 AM
Like
1
Share this post:
Responses (6)
  • Accepted Answer

    Mick L
    Mick L
    Offline
    Wednesday, April 10 2024, 04:38 PM - #Permalink
    Resolved
    0 votes
    It looks like there is another critical security issue, this time with squid. CVE-2023-46847 was fixed in November last year, so ClearOS users will be missing it. Another one Nick Howitt is fixing with his updates -
    clearos@howitts.co.uk
    .
    The reply is currently minimized Show
  • Accepted Answer

    Peter
    Peter
    Offline
    Sunday, March 31 2024, 01:14 PM - #Permalink
    Resolved
    0 votes
    Hi MickL - Ah yeah I see what you are saying. It is an affected version. You are right.
    The reply is currently minimized Show
  • Accepted Answer

    Mick L
    Mick L
    Offline
    Saturday, March 30 2024, 10:49 PM - #Permalink
    Resolved
    0 votes
    The fix was in 2.4.6-97.7. This caused a regression so then 2.4.6-99.1 was released and is the latest upstream. What version are you running?
    The reply is currently minimized Show
  • Accepted Answer

    Peter
    Peter
    Offline
    Saturday, March 30 2024, 11:55 AM - #Permalink
    Resolved
    0 votes
    Yeah - not sure when it happened - but all my ClearOS community servers are running an up to date version of httpd. So updated I guess.
    The reply is currently minimized Show
  • Accepted Answer

    Friday, April 14 2023, 07:02 AM - #Permalink
    Resolved
    0 votes
    I wouldn't expect to much. Even a reply is already too much to ask
    The reply is currently minimized Show
  • Accepted Answer

    nuke
    nuke
    Offline
    Wednesday, April 12 2023, 04:30 PM - #Permalink
    Resolved
    1 votes
    Groan ... Come on Clearcenter ...
    The reply is currently minimized Show
Your Reply