Home server operating system: Updates fix security vulnerabilities in Unraid

Attackers could exploit the gaps to inject their own JavaScript code or malicious plug-ins into the UnRAID admin.

listen Print view
Burning NAS systems

(Image: Bild erstellt mit KI in Bing Image Creator durch heise online / dmk)

2 min. read

Current versions of the Unraid home server operating system fix various security vulnerabilities, some of which are critical. The Unraid team announced this to its customers in a newsletter. Updates are available and admins should install them quickly.

The most serious of the four vulnerabilities is a textbook example of cross-site scripting (XSS): attackers can inject Unraid admins with JavaScript code via a URL parameter in the web-based file browser. However, they must trick their victim into clicking on a crafted link while logged into the Unraid web interface. An XSS is also hidden in a parameter of Unraid's device settings.

2003 has called: This trivial XSS in the Unraid web interface is fixed with current versions.

(Image: heise security / cku)

Videos by heise

In the places:

  • A cross-site request forgery (CSRF) that leads to session theft and possibly code injection,
  • A stored XSS in various database fields – code execution is also possible here.
  • A weakness in the Unraid community App Store that could have allowed attackers to inject malicious application templates after a hostile takeover of a GitHub repository.

All security vulnerabilities have been fixed in the latest major version 7.0.0 released at the beginning of January and in a bugfix release for the previous version. The update has the version number 6.12.15 and also fixes security vulnerabilities in the supplied git and rsync binaries.

Admins who maintain an Unraid server at home or in the company should install the updates quickly.

Empfohlener redaktioneller Inhalt

Mit Ihrer Zustimmung wird hier ein externes YouTube-Video (Google Ireland Limited) geladen.

Ich bin damit einverstanden, dass mir externe Inhalte angezeigt werden. Damit können personenbezogene Daten an Drittplattformen (Google Ireland Limited) übermittelt werden. Mehr dazu in unserer Datenschutzerklärung.

(cku)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.