[Git][security-tracker-team/security-tracker][master] CVE-2020-5407/libspring-security-2.0-java does not affect jessie

Roberto C. Sánchez roberto at debian.org
Mon May 18 20:44:00 BST 2020



Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker


Commits:
356df556 by Roberto C. Sánchez at 2020-05-18T15:43:11-04:00
CVE-2020-5407/libspring-security-2.0-java does not affect jessie

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -19528,6 +19528,7 @@ CVE-2020-5408 (Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2
 	- libspring-security-2.0-java <removed>
 CVE-2020-5407 (Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 ...)
 	- libspring-security-2.0-java <removed>
+	[jessie] - libspring-security-2.0-java <not-affected> (Vulnerable code introduced later)
 CVE-2020-5406 (VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6. ...)
 	NOT-FOR-US: VMware
 CVE-2020-5405 (Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x pri ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/356df556c3ecc47dfb480e9dab732afa7f752bb5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/356df556c3ecc47dfb480e9dab732afa7f752bb5
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200518/0ad21aad/attachment.html>


More information about the debian-security-tracker-commits mailing list