[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] CVE-2017-18076/ruby-omniauth, #888523, fixed in unstable

Salvatore Bonaccorso carnil at debian.org
Wed Jan 31 09:47:03 UTC 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4c8a4196 by Salvatore Bonaccorso at 2018-01-31T10:46:52+01:00
CVE-2017-18076/ruby-omniauth, #888523, fixed in unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -246,7 +246,7 @@ CVE-2017-18077 (index.js in brace-expansion before 1.1.7 is vulnerable to Regula
 	NOTE: nodejs not covered by security support
 CVE-2017-18076 (In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value ...)
 	[experimental] - ruby-omniauth 1.6.1-1
-	- ruby-omniauth <unfixed> (bug #888523)
+	- ruby-omniauth 1.3.1-2 (bug #888523)
 	NOTE: https://github.com/omniauth/omniauth/pull/867
 CVE-2018-6324
 	RESERVED



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/4c8a41960f1cc6094b668a5c48a28b9851838527

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/4c8a41960f1cc6094b668a5c48a28b9851838527
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180131/91299bf5/attachment.html>


More information about the Secure-testing-commits mailing list