[Git][security-tracker-team/security-tracker][master] Update information on CVE-2019-3866

Salvatore Bonaccorso carnil at debian.org
Fri Dec 20 12:38:34 GMT 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
43adcae4 by Salvatore Bonaccorso at 2019-12-20T12:37:44Z
Update information on CVE-2019-3866

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -52748,11 +52748,17 @@ CVE-2019-3867
 	NOT-FOR-US: OpenShift (web-cosnole issue specific to OpenShift only)
 CVE-2019-3866 (An information-exposure vulnerability was discovered where openstack-m ...)
 	- python-oslo.utils <unfixed> (low; bug #946060)
-	[stretch] - python-oslo.utils <not-affected> (regex pattern rewrite)
 	[jessie] - python-oslo.utils <not-affected> (regex pattern rewrite)
+	- python-mistral-lib <unfixed>
+	- mistral 5.1.0-2
+	NOTE: In mistral/5.0.0 the problematic code was moved to the python library.
+	NOTE: To be apply the fixes in mistral/python-mistral-lib as pre-requiste the
+	NOTE: python-oslo.utils package needs an update.
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1768731
 	NOTE: https://bugs.launchpad.net/tripleo/+bug/1850843
 	NOTE: https://opendev.org/openstack/oslo.utils/commit/b41268417cecb12d1d5955ee3107067edf050221
+	NOTE: Patch for Pike and newer: https://launchpadlibrarian.net/449473654/0001-Ensure-we-mask-sensitive-data-from-Mistral-Action-lo.patch
+	NOTE: Patch for Pike and newer: https://launchpadlibrarian.net/449472809/0001-Ensure-we-mask-sensitive-data-from-Mistral-Action-lo.patch
 CVE-2019-3865
 	RESERVED
 	NOT-FOR-US: Quay



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/43adcae419395c70399fecf54c93a98b8e852753

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/43adcae419395c70399fecf54c93a98b8e852753
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191220/ca1bbb81/attachment.html>


More information about the debian-security-tracker-commits mailing list