{"id":"USN-7647-1","summary":"ledgersmb vulnerabilities","details":"It was discovered that LedgerSMB did not check the origin of HTML\nfragments. An attacker could possibly use this issue to send a\nmaliciously crafted URL to the server and obtain sensitive\ninformation, or execute arbitrary code. This issue only affected\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.\n(CVE-2021-3693)\n\nIt was discovered that LedgerSMB did not properly encode HTML\nerror messages. An attacker could possibly use this issue to send\na maliciously crafted URL to the server and obtain sensitive\ninformation, or execute arbitrary code. This issue only affected\nUbuntu 18.04 LTS. (CVE-2021-3694)\n\nIt was discovered that LedgerSMB did not guard against discrete\nlink redirections. An attacker could possibly use this issue to\nobtain sensitive information. This issue only affected Ubuntu\n16.04 LTS and Ubuntu 18.04 LTS. (CVE-2021-3731)\n\nIt was discovered that LedgerSMB did not properly set the 'Secure'\nattribute during HTTPS sessions. If a user were tricked into using\nan unencrypted connection, an attacker could possibly use this\nissue to obtain sensitive information. This issue only affected\nUbuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu\n25.04. (CVE-2021-3882)\n\nIt was discovered that LedgerSMB could create admin accounts via\na URL. If an admin were tricked into clicking a maliciously\ncrafted URL, an attacker could possibly use this issue to\nachieve privilege escalation. This issue only affected Ubuntu 20.04\nLTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.\n(CVE-2024-23831)","modified":"2026-06-25T13:33:22.512675171Z","published":"2025-07-17T14:39:24Z","related":["UBUNTU-CVE-2021-3693","UBUNTU-CVE-2021-3694","UBUNTU-CVE-2021-3731","UBUNTU-CVE-2021-3882","UBUNTU-CVE-2024-23831"],"upstream":["CVE-2021-3693","CVE-2021-3694","CVE-2021-3731","CVE-2021-3882","CVE-2024-23831","UBUNTU-CVE-2021-3693","UBUNTU-CVE-2021-3694","UBUNTU-CVE-2021-3731","UBUNTU-CVE-2021-3882","UBUNTU-CVE-2024-23831"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7647-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3693"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3694"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3731"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3882"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-23831"}],"affected":[{"package":{"name":"ledgersmb","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/ledgersmb?arch=source&distro=esm-apps%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.46-1ubuntu0.1~esm1"}]}],"versions":["1.3.46-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.3.46-1ubuntu0.1~esm1","binary_name":"ledgersmb"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2021-3693","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2021-3731","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:16.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7647-1.json"}},{"package":{"name":"ledgersmb","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/ledgersmb?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.42+ds-1ubuntu0.1~esm1"}]}],"versions":["1.4.41+ds-1","1.4.42+ds-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.4.42+ds-1ubuntu0.1~esm1","binary_name":"ledgersmb"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2021-3693"},{"id":"CVE-2021-3694","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2021-3731","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7647-1.json"}},{"package":{"name":"ledgersmb","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/ledgersmb?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.9+ds-1ubuntu0.1+esm1"}]}],"versions":["1.6.9+ds-1","1.6.9+ds-1ubuntu0.1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"ledgersmb","binary_version":"1.6.9+ds-1ubuntu0.1+esm1"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2021-3882"},{"id":"CVE-2024-23831","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7647-1.json"}},{"package":{"name":"ledgersmb","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/ledgersmb?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.33+ds-1ubuntu0.1"}]}],"versions":["1.6.9+ds-2.1","1.6.33+ds-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"ledgersmb","binary_version":"1.6.33+ds-1ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7647-1.json","cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2021-3693"},{"id":"CVE-2021-3882","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2024-23831","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:22.04:LTS"}}},{"package":{"name":"ledgersmb","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/ledgersmb?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.33+ds-2.1ubuntu0.1"}]}],"versions":["1.6.33+ds-2.1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.6.33+ds-2.1ubuntu0.1","binary_name":"ledgersmb"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:24.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2021-3693"},{"id":"CVE-2021-3882","severity":[{"score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-23831","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7647-1.json"}}],"schema_version":"1.7.5"}