ProxmoxSecurityAdvisory's latest activity

  • ProxmoxSecurityAdvisory
    Subject: PSA-2025-00020-1: Missing protections against malicious backup clients with S3-backed datastores Advisory date: 2025-10-27 Packages: proxmox-backup-server Details: On datastores configured with an S3 backend, a malicious client could...
  • ProxmoxSecurityAdvisory
    Subject: PSA-2025-00019-1: Race condition during long-running garbage collection and pruning of recent snapshots may lead to back up corruption before Proxmox Backup Server 3.4 Advisory date: 2025-10-27 Packages: proxmox-backup-server Details...
  • ProxmoxSecurityAdvisory
    Subject: PSA-2025-00018-1: buffer overflow in vncterm/spiceterm handling of ANSI escape sequences Advisory date: 2025-09-22 Packages: vncterm, spiceterm Details: vncterm and spiceterm are utilies that are spawned when initiating a VNC or SPICE...
  • ProxmoxSecurityAdvisory
    Subject: PSA-2025-00017-1: pre-generated "snakeoil" certificate in container templates Advisory date: 2025-09-17 Packages: pve-container Details: Any Debian-based container template that includes the "ssl-cert" package contains a self-signed...
  • ProxmoxSecurityAdvisory
    Subject: PSA-2025-00016-1: Spectre branch target injection from VM guests ("VMScape") Advisory date: 2025-09-17 Packages: proxmox-kernel-6.8, proxmox-kernel-6.14 Details: Incomplete branch predictor isolation mechanisms allow exploitation of...
  • ProxmoxSecurityAdvisory
    Subject: PSA-2025-00016-1: Spectre branch target injection from VM guests ("VMScape") Advisory date: 2025-09-17 Packages: proxmox-kernel-6.8, proxmox-kernel-6.14 Details: Incomplete branch predictor isolation mechanisms allow exploitation of...
  • ProxmoxSecurityAdvisory
    Subject: PSA-2025-00016-1: Spectre branch target injection from VM guests ("VMScape") Advisory date: 2025-09-17 Packages: proxmox-kernel-6.8, proxmox-kernel-6.14 Details: Incomplete branch predictor isolation mechanisms allow exploitation of...
  • ProxmoxSecurityAdvisory
    Subject: PSA-2025-00015-1: stored XSS in config values Advisory date: 2025-09-04 Packages: pmg-gui Details: The HTTP proxy setting dialogue in the web interface was susceptible to XSS. Editing this setting is only available to users with admin...
  • ProxmoxSecurityAdvisory
    Subject: PSA-2025-00014-1: stored XSS in config values Advisory date: 2025-08-14 Packages: proxmox-backup-server Details: The WebAuthN setting dialogue in the web interface was susceptible to XSS. Editing these settings requires root...
  • ProxmoxSecurityAdvisory
    Subject: PSA-2025-00013-1: stored XSS in config values Advisory date: 2025-08-14 Packages: pve-manager Details: The HTTP proxy, WebAuthN and U2F setting dialogues in the web interface were susceptible to XSS. Editing these settings requires...