Vulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that the users would have uploaded in their raw SCM repositories (SVN, Git, Bzr...). This issue affects fusionforge: before 5.3+20140506.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "fusionforge",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-common",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-db-local",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-db-remote",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-lists",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-mta-exim4",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-mta-postfix",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-admssw",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-authcas",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-authhttpd",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-authldap",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-blocks",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-compactpreview",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-contribtracker",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-doaprdf",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-extsubproj",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-foafprofiles",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-globalsearch",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-gravatar",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-headermenu",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-hudson",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-mediawiki",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-message",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-moinmoin",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-projectlabels",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-scmarch",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-scmbzr",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-scmcvs",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-scmdarcs",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-scmgit",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-scmhg",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-scmhook",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-scmsvn",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-sysauthldap",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-taskboard",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-plugin-webanalytics",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-scm",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-shell",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-web",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "fusionforge-web-vhosts",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "gforge-common",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "gforge-db-postgresql",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "gforge-db-remote",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "gforge-lists-mailman",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "gforge-mta-exim4",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "gforge-mta-postfix",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "gforge-shell-postgresql",
"binary_version": "6.0.2+20150708-1"
},
{
"binary_name": "gforge-web-apache2",
"binary_version": "6.0.2+20150708-1"
}
]
}