Debian Patches

Status for ocsinventory-server/2.8.1+dfsg1-1+deb11u1

Patch Description Author Forwarded Bugs Origin Last update
apache_conf_name Fix apache conf file name in help messages Jean-Michel Vourgère <nirgal@debian.org> no 2018-05-03
fix_tools-install_plugin.py-paths.patch Fix_tools install_plugin.py paths no
fix-ocsreports-paths.patch Fix OCS-reports paths Cyrille Bollu <cyrille@bollu.be> not-needed 2019-01-17
use_system_libraries Use Debian packaged libraries Jean-Michel Vourgère <nirgal@debian.org> not-needed 2018-08-02
fix-php-cas-api-change-for-cve-2023-39369.patch Adapt ocsinventory to API-breaking change of php-cas/CVE-2022-39369

The mitigation of CVE-2022-39369 required a change in php-cas, namely proving
the Baseurl of the service to be authenticated. This patch adapts the ocsinventory
to the changed API.
Tobias Frost <tobi@debian.org> not-needed debian 2023-07-06
0006-Fix-vendored-CVE-2022-39369.patch Fix vendored CVE-2022-39369
Merge pull request from GHSA-8q72-6qq8-xv64

* Add ServerName classes and required service_name constructor argument

This includes a refactoring of moving Client->_getClientUrl() method to a new class.

Unit tests are also added and updated for the new constructor argument.

* Add service_name argument to the static helper class and examples

* Update docs for 1.6.0 release

* Update versions for the 1.6.0 release

* Rename ServerName class to ServiceBaseUrl and add protocol in allowedlist check

* Update docs for the ServiceBaseUrl class and argument change

* Minor typo fixes
Phy <git@phy25.com> no 2022-10-31

All known versions for source package 'ocsinventory-server'

Links