[horde] another security issue discovered in Horde ref. CVE-2022-30287

Jens Wahnes wahnes at uni-koeln.de
Mon Jun 27 07:48:58 UTC 2022


Michael,

Michael J Rubinsky wrote:
>>> The problem is with virtual address books. If one decides to save an 
>>> addressbook search as a virtual address book, the issue of "$config 
>>> must be an array" will come up as soon as one clicks on "Address 
>>> Book" in dynamic mode.
>> That does indeed help narrow things down. I'll take a look when I can.
> Fixed in 4.2.29

just wanted to say Thank You.  The fix in Turba 4.2.29 does indeed 
resolve the issue here at our site.  After I applied that update, no 
"config must be an array" messages have come up in the log files 
anymore.  Not for users of virtual addressbooks nor for users of any 
other seldomly used Horde feature.


Jens
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5324 bytes
Desc: S/MIME Cryptographic Signature
URL: <https://lists.horde.org/archives/horde/attachments/20220627/2a4841ce/attachment.bin>


More information about the horde mailing list