security: fix CVE 2022 46172 (#4275)

* fallback to current user in user_write, add flag to disable user creation

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>

* update api and web ui

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>

* update default flows

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>

* add cve post to website

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>

* add tests

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>
This commit is contained in:
Jens L
2022-12-23 14:12:58 +01:00
committed by Jens Langhammer
parent 44bf9a890e
commit 47d79ac28c
17 changed files with 167 additions and 25 deletions

View File

@ -290,7 +290,11 @@ module.exports = {
title: "Security",
slug: "security",
},
items: ["security/policy", "security/CVE-2022-46145"],
items: [
"security/policy",
"security/CVE-2022-46145",
"security/CVE-2022-46172",
],
},
],
};