[Git][security-tracker-team/security-tracker][master] CVE-2021-29157/dovecot: Add reference to dovecot-news announce

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jun 21 15:20:12 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0ebde854 by Salvatore Bonaccorso at 2021-06-21T16:19:37+02:00
CVE-2021-29157/dovecot: Add reference to dovecot-news announce

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -14005,6 +14005,7 @@ CVE-2021-29157 [oauth2 JWT local validation path traversal]
 	- dovecot <unfixed>
 	[buster] - dovecot <not-affected> (Vulnerable code introduced later)
 	[stretch] - dovecot <not-affected> (Vulnerable code introduced later)
+	NOTE: https://dovecot.org/pipermail/dovecot-news/2021-June/000461.html
 CVE-2021-29156 (ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger ...)
 	NOT-FOR-US: ForgeRock OpenAM
 CVE-2021-29155 (An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ebde854fcdbbecdea991840d05268f172c45344

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ebde854fcdbbecdea991840d05268f172c45344
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210621/74be05b9/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list