[Bug 293922] net-mgmt/unify9,10 security vulnerabilities

From: <bugzilla-noreply_at_freebsd.org>
Date: Thu, 19 Mar 2026 19:05:29 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=293922

            Bug ID: 293922
           Summary: net-mgmt/unify9,10 security vulnerabilities
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: Individual Port(s)
          Assignee: ports-bugs@FreeBSD.org
          Reporter: fernape@FreeBSD.org

From Jana Steuernagel

Unifi has published a security advisory for the Unifi Controller version
10.1.85 and below, which is the current version on Ports.

It includes 2 CVEs, one with a score of 10.0, allowing path traversal to access
files on the underlying system, and a 7.7 NoSQL injection, allowing privilege
escalation for authenticated users.

https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b

A patched version 10.1.89 is available and it would be great if that could be
updated in Ports soon:

https://community.ui.com/releases/UniFi-Network-Application-10-1-89/625f366f-7ea5-4266-bd9f-500180494035

-- 
You are receiving this mail because:
You are the assignee for the bug.