[Git][security-tracker-team/security-tracker][master] 2 commits: Triage CVE-2021-28834 in ruby-kramdown for stretch LTS.
Chris Lamb
lamby at debian.org
Sat Mar 20 10:34:36 GMT 2021
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c40a35a2 by Chris Lamb at 2021-03-20T10:33:26+00:00
Triage CVE-2021-28834 in ruby-kramdown for stretch LTS.
- - - - -
3aea448f by Chris Lamb at 2021-03-20T10:34:20+00:00
data/dla-needed.txt: Triage ruby-carrierwave for stretch LTS (CVE-2021-21288).
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -242,6 +242,7 @@ CVE-2021-28835
RESERVED
CVE-2021-28834 (Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge: ...)
- ruby-kramdown <unfixed> (bug #985569)
+ [buster] - ruby-kramdown <not-affected> (Vulnerable code added later)
NOTE: https://github.com/gettalong/kramdown/pull/708
NOTE: Fixed by: https://github.com/gettalong/kramdown/commit/d6a1cbcb2caa2f8a70927f176070d126b2422760
CVE-2021-28833
=====================================
data/dla-needed.txt
=====================================
@@ -105,6 +105,10 @@ ruby-actionpack-page-caching
--
ruby-activerecord-session-store
--
+ruby-carrierwave
+ NOTE: 20210320: Will be difficult to backport as code in LTS version appears
+ NOTE: 20210320: to use primitive Kernel.open to load URIs. (lamby)
+--
ruby-doorkeeper
NOTE: 20200831: it's a breaking change, I'd rather not want to issue a DLA for this. (utkarsh)
NOTE: 20200831: in case it's really DLA worthy, I'd be very careful with this update. (utkarsh)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0d369987a95b5155cef768b3f7dcb979758f2364...3aea448fef0b78331cbc842897ef8e6f9126cafd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0d369987a95b5155cef768b3f7dcb979758f2364...3aea448fef0b78331cbc842897ef8e6f9126cafd
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210320/1d01acb0/attachment.htm>
More information about the debian-security-tracker-commits
mailing list