Skip to content

Conversation

@james-d-elliott
Copy link
Contributor

@james-d-elliott james-d-elliott commented May 10, 2022

linuxserver.io


  • I have read the contributing guideline and understand that I have made the correct modifications

Description:

This is NOT a security fix. The following addresses a problem with Synology which uses a non-standard char in the DSM application {}. This alleviates this issue. I don't believe it needs to be fixed in existing configs but I'll leave that up to you.

I think another option would be removing this check entirely as the version affected in the original CVE is over a year old at this point. Let me know what you think. I have not expressly checked the change to 50-config but I suspect that'll be picked up in CI.

Benefits of this PR and context:

How Has This Been Tested?

Source / References:

@LinuxServer-CI
Copy link
Contributor

@GeoCookie
Copy link

I think there is a mistake. The block you add \{\} should be before the closing brackets ])
I hope I'm not saying something stupid

@james-d-elliott
Copy link
Contributor Author

I think there is a mistake. The block you add \{\} should be before the closing brackets ]) I hope I'm not saying something stupid

You're absolutely right, thanks for spotting @GeoCookie, does that look better?

@aptalca aptalca self-assigned this May 10, 2022
@LinuxServer-CI
Copy link
Contributor

@james-d-elliott
Copy link
Contributor Author

james-d-elliott commented May 12, 2022

Related: #213

I can either probably combine this into #213 or we can opt to remove it entirely. Users who don't update authelia should already have this patch from swag, and should realistically update anyway since the CVE notice has long been available. Users setting up a new install of Authelia should be using the latest version, and thus don't need this workaround (which was intended as a temporary one to mitigate issues for users who don't pay attention to security things).

GHSA-68wm-pfjf-wqp6

As one of the team member I'm more than willing to provide people backported fixes for old versions if they prefer, however we strongly recommend upgrading.

@github-actions
Copy link

This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@james-d-elliott
Copy link
Contributor Author

This is being handled by a pending change. Closing.

@james-d-elliott james-d-elliott deleted the fix-authelia-401 branch August 9, 2022 01:03
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Apr 5, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants