OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the AuthType
is set to anything but Basic
, if the request contains an Authorization: Basic ...
header, the password is not checked. This results in authentication bypass. Any configuration that allows an AuthType
that is not Basic
is affected. Version 2.4.13 fixes the issue.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 10 | RedHat | cups-1:2.4.10-11.el10_0.1 | * |
Red Hat Enterprise Linux 8 | RedHat | cups-1:2.2.6-63.el8_10 | * |
Red Hat Enterprise Linux 8 | RedHat | cups-1:2.2.6-63.el8_10 | * |
Red Hat Enterprise Linux 9 | RedHat | cups-1:2.3.3op2-33.el9_6.1 | * |
Red Hat Enterprise Linux 9 | RedHat | cups-1:2.3.3op2-33.el9_6.1 | * |
Cups | Ubuntu | devel | * |
Cups | Ubuntu | esm-infra/bionic | * |
Cups | Ubuntu | esm-infra/focal | * |
Cups | Ubuntu | esm-infra/xenial | * |
Cups | Ubuntu | jammy | * |
Cups | Ubuntu | noble | * |
Cups | Ubuntu | plucky | * |
Cups | Ubuntu | upstream | * |