← Back to team overview

group.of.nepali.translators team mailing list archive

[Bug 1571491] Re: possible auth bypass

 

This bug was fixed in the package snapd - 2.0.1

---------------
snapd (2.0.1) xenial; urgency=medium

  * client,daemon,overlord: fix authentication:
    - fix incorrect authenication check (LP: #1571491)

 -- Michael Vogt <michael.vogt@xxxxxxxxxx>  Mon, 18 Apr 2016 07:24:33
+0200

** Changed in: snapd (Ubuntu Xenial)
       Status: In Progress => Fix Released

-- 
You received this bug notification because you are a member of नेपाली
भाषा समायोजकहरुको समूह, which is subscribed to Xenial.
Matching subscriptions: Ubuntu 16.04 Bugs
https://bugs.launchpad.net/bugs/1571491

Title:
  possible auth bypass

Status in snapd package in Ubuntu:
  Fix Released
Status in snapd source package in Xenial:
  Fix Released

Bug description:
  The snapd authentication can by bypassed by sending invalid auth:
  headers and logout is not revmoing the local authentication data.

  Regression potential: worst case is that snap authentication no longer
  works which is preferable to an auth bypass.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/snapd/+bug/1571491/+subscriptions


References