Hi,
a vulnerability was discovered in sabnzbdplus that allows any client
with access to the password-protected web interface to obtain an
authenticated session without knowing the username or password.
Affected versions are all since 3.0.0 through 5.1.0; for Debian that
translates to every release since bullseye. Fixed in upstream release
5.1.1, meanwhile uploaded to unstable as 5.1.1+dfsg-1.
CVE: [not yet]
Github: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-xrfq-jhgh-wqch
Fix: https://github.com/sabnzbd/sabnzbd/commit/9a12300877a38becda23dada37fd4f9c488801a5
Patches (source debdiff) for the sabnzbdplus package in bookworm and
trixie are attached, and published in the {bookworm,trixie}-security
branches in the package's VCS on salsa. Both have been verified to
build, install, run, and fix the security issue.