[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso
carnil at debian.org
Sun May 3 21:10:29 BST 2020
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c2a40422 by security tracker role at 2020-05-03T20:10:22+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,5 @@
+CVE-2020-12624 (The League application before 2020-05-02 on Android sends a bearer tok ...)
+ TODO: check
CVE-2020-12623
RESERVED
CVE-2020-12622
@@ -27781,7 +27783,7 @@ CVE-2020-1940 (The optional initial password change and password expiration feat
CVE-2020-1939
RESERVED
CVE-2020-1938 (When using the Apache JServ Protocol (AJP), care must be taken when tr ...)
- {DLA-2133-1}
+ {DSA-4673-1 DLA-2133-1}
- tomcat9 9.0.31-1 (bug #952437)
- tomcat8 <removed> (bug #952438)
[jessie] - tomcat8 <no-dsa> (backport is intrusive because of API changes)
@@ -27808,7 +27810,7 @@ CVE-2020-1937 (Kylin has some restful apis which will concatenate SQLs with the
CVE-2020-1936
RESERVED
CVE-2020-1935 (In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0. ...)
- {DLA-2133-1}
+ {DSA-4673-1 DLA-2133-1}
- tomcat9 9.0.31-1
- tomcat8 <removed>
[jessie] - tomcat8 <no-dsa> (backport is too intrusive)
@@ -36713,7 +36715,7 @@ CVE-2019-17570 (An untrusted deserialization was found in the org.apache.xmlrpc.
NOTE: Proposed patch: https://bugzilla.redhat.com/show_bug.cgi?id=1775193
NOTE: https://github.com/orangecertcc/xmlrpc-common-deserialization
CVE-2019-17569 (The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8 ...)
- {DLA-2133-1}
+ {DSA-4673-1 DLA-2133-1}
- tomcat9 9.0.31-1
- tomcat8 <removed>
[jessie] - tomcat8 <not-affected> (vulnerable code introduced in later version)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c2a404229fbfe699b1ab9f97cfe3d71e17529d44
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c2a404229fbfe699b1ab9f97cfe3d71e17529d44
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200503/7b08959a/attachment.html>
More information about the debian-security-tracker-commits
mailing list