diff options
| author | Linus Heckemann <git@sphalerite.org> | 2022-05-31 17:28:33 +0200 |
|---|---|---|
| committer | Linus Heckemann <git@sphalerite.org> | 2022-06-01 12:31:23 +0200 |
| commit | 7eab23d517cfd3a2e8d40e0d72cdb8fb0969bf9a (patch) | |
| tree | c4937dc169d507f19691f49bba224ac3eb2bcd8e /pkgs/development/python-modules/termplotlib/gnuplot-subprocess.patch | |
| parent | 084930fa14899d5eb95c9326bb6f69a5239d61e6 (diff) | |
jellyfin: fix permissions on state directory
Previously, all configuration and state data was accessible to all
users on the system running jellyfin. This included user passwords in
the Jellyfin database, as well as credentials for LDAP if configured.
The exact set of accessible data depends on system configuration.
Thanks to Sofie Finnes Øvrelid for reporting this issue.
Fixes: CVE-2022-32198
Co-Authored-By: Martin Weinelt <hexa@darmstadt.ccc.de>
Diffstat (limited to 'pkgs/development/python-modules/termplotlib/gnuplot-subprocess.patch')
0 files changed, 0 insertions, 0 deletions
