Information on source package sabnzbdplus

Available versions

ReleaseVersion
bookworm/contrib3.7.1+dfsg-2
trixie/contrib4.5.0+dfsg-1+deb13u1
forky/contrib5.1.3+dfsg-1
sid/contrib5.1.3+dfsg-1

Open issues

BugbookwormtrixieforkysidDescription
TEMP-1147154-ECE4C7vulnerablevulnerablefixedfixedGHSA-mjwj-v5mr-cmcg: PAR2 symlink bypass allows pickle remote code execution.
TEMP-1147154-EA5624vulnerablevulnerablefixedfixedGHSA-q326-jpxx-jmjc: __wrapped__ dispatch bypass allows unauthenticated API access
TEMP-1145563-F10EE7vulnerablevulnerablefixedfixedGHSA-75g3-96fr-7p2r: SABnzbd PAR2 path traversal enabling cross-job __verified__ pickle RCE
TEMP-1145563-076BF6vulnerablevulnerablefixedfixedGHSA-rgqj-28c2-gxwp: Unauthenticated API mode confusion allows configuration takeover and remote code execution
TEMP-1144839-91D17BvulnerablefixedfixedfixedGHSA-xrfq-jhgh-wqch: Authentication bypass in the web interface
CVE-2023-34237vulnerable (no DSA)fixedfixedfixedSABnzbd is an open source automated Usenet download tool. A design fla ...

Resolved issues

BugDescription
TEMP-0593829-E6A4BCconfig file world readable
CVE-2021-29488SABnzbd is an open source binary newsreader. A vulnerability was disco ...
CVE-2020-13124SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in ...

Security announcements

DSA / DLADescription
DSA-6454-1sabnzbdplus - security update

Search for package or bug name: Reporting problems