<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://en.wiki.bluespice.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Zhayat</id>
	<title>BlueSpice Helpdesk - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://en.wiki.bluespice.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Zhayat"/>
	<link rel="alternate" type="text/html" href="https://en.wiki.bluespice.com/wiki/Special:Contributions/Zhayat"/>
	<updated>2026-08-17T13:16:32Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.9</generator>
	<entry>
		<id>https://en.wiki.bluespice.com/w/index.php?title=Security:Security_Advisories/BSSA-2026-05&amp;diff=14526</id>
		<title>Security:Security Advisories/BSSA-2026-05</title>
		<link rel="alternate" type="text/html" href="https://en.wiki.bluespice.com/w/index.php?title=Security:Security_Advisories/BSSA-2026-05&amp;diff=14526"/>
		<updated>2026-07-21T11:41:13Z</updated>

		<summary type="html">&lt;p&gt;Zhayat: Added CVE-2025-65896&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
|Date&lt;br /&gt;
|2026-07-17&lt;br /&gt;
|-&lt;br /&gt;
|Severity&lt;br /&gt;
|reported &amp;quot;high&amp;quot;, BlueSpice assessment: &#039;&#039;&#039;not affected&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|Affected&lt;br /&gt;
|&amp;lt;code&amp;gt;bluespice/search&amp;lt;/code&amp;gt; Docker image (all versions)&lt;br /&gt;
&amp;lt;code&amp;gt;bluespice/ai&amp;lt;/code&amp;gt; Docker image (5.3.x)&lt;br /&gt;
|-&lt;br /&gt;
|Fixed in&lt;br /&gt;
|Unknown&lt;br /&gt;
|-&lt;br /&gt;
|CVE&lt;br /&gt;
|&lt;br /&gt;
* [https://access.redhat.com/security/cve/cve-2025-14813 CVE-2025-14813]&lt;br /&gt;
* [https://nvd.nist.gov/vuln/detail/CVE-2025-65896 CVE-2025-65896]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Problem==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!&#039;&#039;&#039;CVE&#039;&#039;&#039;&lt;br /&gt;
!&#039;&#039;&#039;Component&#039;&#039;&#039;&lt;br /&gt;
!&#039;&#039;&#039;Type of vulnerability&#039;&#039;&#039;&lt;br /&gt;
!&#039;&#039;&#039;BlueSpice 5&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|CVE-2025-14813&lt;br /&gt;
|&amp;lt;code&amp;gt;bluespice/search&amp;lt;/code&amp;gt;&lt;br /&gt;
|Use of a Broken or Risky Cryptographic Algorithm&lt;br /&gt;
| style=&amp;quot;&amp;quot; class=&amp;quot;col-green-bg&amp;quot; |not affected&lt;br /&gt;
|-&lt;br /&gt;
|CVE-2025-65896&lt;br /&gt;
|&amp;lt;code&amp;gt;bluespice/ai&amp;lt;/code&amp;gt;&lt;br /&gt;
|SQL Injection via dictionary as params&lt;br /&gt;
| style=&amp;quot;&amp;quot; class=&amp;quot;col-green-bg&amp;quot; |not affected&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Impact assessment==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
!CVE&lt;br /&gt;
!Assessment&lt;br /&gt;
!Mitigation without update&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;vertical-align:middle;text-align:left;&amp;quot; |CVE-2025-14813&lt;br /&gt;
| style=&amp;quot;vertical-align:middle;text-align:left;&amp;quot; class=&amp;quot;col-green-bg&amp;quot; |The code is only used by Tika when processing Encrypted PDFs and Office files, which we don&#039;t support. In addition the code affected in particular is probably not used and the described attack vector (&amp;quot;capture ciphertext&amp;quot;) and impact (&amp;quot;perform cryptanalysis and uncover the underlying data&amp;quot;) is not applicable in this use case. &lt;br /&gt;
| style=&amp;quot;vertical-align:middle;text-align:left;&amp;quot; |No action required.&lt;br /&gt;
|-&lt;br /&gt;
|CVE-2025-65896&lt;br /&gt;
| style=&amp;quot;&amp;quot; class=&amp;quot;col-green-bg&amp;quot; |Asyncmy is only used as the DB API layer for SQLAlchemy to connect to MySQL, SQLAlchemy enforces a &amp;quot;format&amp;quot; parameter style, which only uses &amp;quot;%s&amp;quot; placeholder strings for SQL queries. This is opposed to inserting values via a dictionary, meaning no impact from this CVE is possible.&lt;br /&gt;
|No action required.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Solution ==&lt;br /&gt;
No immediate action required.&lt;/div&gt;</summary>
		<author><name>Zhayat</name></author>
	</entry>
	<entry>
		<id>https://en.wiki.bluespice.com/w/index.php?title=Setup:Installation_Guide/Docker/Pro_and_Farm_edition&amp;diff=13094</id>
		<title>Setup:Installation Guide/Docker/Pro and Farm edition</title>
		<link rel="alternate" type="text/html" href="https://en.wiki.bluespice.com/w/index.php?title=Setup:Installation_Guide/Docker/Pro_and_Farm_edition&amp;diff=13094"/>
		<updated>2025-10-15T12:56:35Z</updated>

		<summary type="html">&lt;p&gt;Zhayat: Fixed typo&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Almost all container images used by the stack are freely available via hub.docker.com. The only exception is &amp;lt;code&amp;gt;bluespice/wiki&amp;lt;/code&amp;gt; with the PRO / FARM codebase. There are two options to obtain this image:&lt;br /&gt;
&lt;br /&gt;
# Manual download from [https://bluespice.com/download/ bluespice.com] and local import&lt;br /&gt;
# Load from private &amp;lt;code&amp;gt;docker.bluespice.com&amp;lt;/code&amp;gt; image registry&lt;br /&gt;
&lt;br /&gt;
== Manual download and import ==&lt;br /&gt;
Before running &amp;lt;code&amp;gt;bluespice-deploy&amp;lt;/code&amp;gt; you will need to download the &amp;lt;code&amp;gt;docker.bluespice.com/bluespice-[pro|farm]/wiki&amp;lt;/code&amp;gt; image from https://bluespice.com/download/ and store the file to the server (e.g. in &amp;lt;code&amp;gt;/tmp/docker.bluespice.com_bluespice-pro_wiki_5.1.0.tar.gz&amp;lt;/code&amp;gt; ).&lt;br /&gt;
&lt;br /&gt;
Then you can use the standard &amp;lt;code&amp;gt;docker load&amp;lt;/code&amp;gt; command to make it available to the docker runtime.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
 docker load &amp;lt; /tmp/docker.bluespice.com_bluespice-pro_wiki_5.1.0.tar.gz&lt;br /&gt;
 # Loaded image: docker.bluespice.com/bluespice-pro/wiki:5.1.0&lt;br /&gt;
 bluespice-deyploy up -d&lt;br /&gt;
 # Image found locally.&lt;br /&gt;
&lt;br /&gt;
== Load from &amp;lt;code&amp;gt;docker.bluespice.com&amp;lt;/code&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
If you have credentials to &amp;lt;code&amp;gt;docker.bluespice.com&amp;lt;/code&amp;gt; you can just run &amp;lt;code&amp;gt;bluespice-deyploy up -d&amp;lt;/code&amp;gt; . It will prompt you for username and password in case you haven&#039;t configured it already.&lt;br /&gt;
&lt;br /&gt;
​Example:&lt;br /&gt;
&lt;br /&gt;
 bluespice-deploy up -d&lt;br /&gt;
 # In order to access our PRO-Image please login to docker.bluespice.com&lt;br /&gt;
 username: myuser&lt;br /&gt;
 password:&lt;br /&gt;
&lt;br /&gt;
[[de:Setup:Installationsanleitung/Docker/Pro_und_Farm_Edition]]&lt;/div&gt;</summary>
		<author><name>Zhayat</name></author>
	</entry>
	<entry>
		<id>https://en.wiki.bluespice.com/w/index.php?title=User:Zhayat&amp;diff=13078</id>
		<title>User:Zhayat</title>
		<link rel="alternate" type="text/html" href="https://en.wiki.bluespice.com/w/index.php?title=User:Zhayat&amp;diff=13078"/>
		<updated>2025-10-10T07:01:36Z</updated>

		<summary type="html">&lt;p&gt;Zhayat: create user page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Userpage standard content}}&lt;/div&gt;</summary>
		<author><name>Zhayat</name></author>
	</entry>
	<entry>
		<id>https://en.wiki.bluespice.com/w/index.php?title=User_blog:Zhayat&amp;diff=13077</id>
		<title>User blog:Zhayat</title>
		<link rel="alternate" type="text/html" href="https://en.wiki.bluespice.com/w/index.php?title=User_blog:Zhayat&amp;diff=13077"/>
		<updated>2025-10-10T07:01:36Z</updated>

		<summary type="html">&lt;p&gt;Zhayat: Root blog page created&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Zhayat</name></author>
	</entry>
</feed>