Wednesday, December 22, 2021

Current 0-day vulnerability on FreePBX

Hey,

We’re working on getting a fix pushed out, hopefully within the next 24 hours or so. It’s a very recently introduced problem so only impacts you if you have the following restapps versions installed:

16.0.18.40
16.0.18.41
15.0.19.87
15.0.19.88

Blocking public traffic to the restapps port on public interfaces is a good mitigation. Or downgrade restapps to anything before those versions is probably a better option.

If you roll back to 15.0.19.86 or 16.0.18.39 you should be ok.

Sorry about the trouble on this, we’re working as quickly as possible to get this resolved.

Matthew Fredrickson

EDIT: @tm1000 thinks that blocking restapps ports is still insufficient from his testing, so downgrading is the best path until the official fix is pushed.



from Hacker News https://ift.tt/3H9Qkw1

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.