NIXPKGS-2026-0149
GitHub issue
published on 7 Feb 2026
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
5 packages
- asterisk-ldap
- asterisk-module-sccp
- python312Packages.asterisk-mbox
- python313Packages.asterisk-mbox
- python314Packages.asterisk-mbox
- @LeSuisse accepted
- @LeSuisse published on GitHub
The Asterisk embedded web server 's /httpstatus page echos user supplied values(cookie and query string) without sanitization
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET variable query Parameter are directly interpolated into the HTML of the page using ast_str_append. The endpoint at GET /httpstatus is the potential vulnerable endpoint relating to asterisk/main /http.c. This issue has been patched in versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2.
Affected products
asterisk
- ==< 23.2.2
- ==< 21.12.1
- ==< 20.7-cert9
- ==< 20.18.2
- ==< 22.8.2
Matching in nixpkgs
pkgs.asterisk_18
Software implementation of a telephone private branch exchange (PBX)
pkgs.asterisk_20
Software implementation of a telephone private branch exchange (PBX)
pkgs.asterisk_22
Software implementation of a telephone private branch exchange (PBX)
Package maintainers
-
@auntieNeo Jonathan Glines <auntieNeo@gmail.com>
-
@yorickvP Yorick van Pelt <yorickvanpelt@gmail.com>
-
@DerTim1 Tim Digel <tim.digel@active-group.de>