The Learn FreeNAS blog reported about two recently found security flaws in FreeNAS, which will only affect those connected to the internet.
- Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
- Cross-site request forgery (CSRF) vulnerability in the WebGUI in FreeNAS before 0.7RC1 allows remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.
Related posts:
- FreeBSD Security Advisories (ftpd & protosw)
- FreeBSD Security Advisories (openssl & lukemftpd)
- FreeNAS 0.7RC1 (Sardaukar) released
- beta release: FreeNAS 0.69b3
- Released: FreeNAS 0.7.1



Fri, Aug 28, 2009
FreeNAS