[Git][security-tracker-team/security-tracker][master] Mark CVE-2020-18670,CVE-2020-18671 in roundcube as ignore instead of postponed

Markus Koschany (@apo) apo at debian.org
Mon Dec 6 16:42:48 GMT 2021



Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b8e325e5 by Markus Koschany at 2021-12-06T17:34:28+01:00
Mark CVE-2020-18670,CVE-2020-18671 in roundcube as ignore instead of postponed

Those issues are borderline unimportant and can be safely ignored.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -96737,13 +96737,13 @@ CVE-2020-18672
 CVE-2020-18671 (Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4  ...)
 	- roundcube 1.4.5+dfsg.1-1
 	[buster] - roundcube 1.3.13+dfsg.1-1~deb10u1
-	[stretch] - roundcube <postponed> (Minor issue, XSS in installer which is not exposed in Debian)
+	[stretch] - roundcube <ignored> (Minor issue, XSS in installer which is not exposed in Debian)
 	NOTE: https://github.com/roundcube/roundcubemail/issues/7406
 	NOTE: https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12
 CVE-2020-18670 (Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via d ...)
 	- roundcube 1.4.5+dfsg.1-1
 	[buster] - roundcube 1.3.13+dfsg.1-1~deb10u1
-	[stretch] - roundcube <postponed> (Minor issue, XSS in installer which is not exposed in Debian)
+	[stretch] - roundcube <ignored> (Minor issue, XSS in installer which is not exposed in Debian)
 	NOTE: https://github.com/roundcube/roundcubemail/issues/7406
 	NOTE: https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12
 CVE-2020-18669



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b8e325e5edb09a52d5e195df3f1b6af7082245c7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b8e325e5edb09a52d5e195df3f1b6af7082245c7
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211206/7ef0f282/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list