[Git][security-tracker-team/security-tracker][master] Add CVE-2022-3109{0,1}/guzzle

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jun 28 21:46:19 BST 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f47ed348 by Salvatore Bonaccorso at 2022-06-28T22:45:46+02:00
Add CVE-2022-3109{0,1}/guzzle

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9441,9 +9441,13 @@ CVE-2022-31093 (NextAuth.js is a complete open source authentication solution fo
 CVE-2022-31092 (Pimcore is an Open Source Data & Experience Management Platform. P ...)
 	NOT-FOR-US: Pimcore
 CVE-2022-31091 (Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` he ...)
-	TODO: check
+	- guzzle <unfixed>
+	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-q559-8m2m-g699
+	NOTE: https://github.com/guzzle/guzzle/commit/1dd98b0564cb3f6bd16ce683cb755f94c10fbd82 (7.4.5)
 CVE-2022-31090 (Guzzle, an extensible PHP HTTP client. `Authorization` headers on requ ...)
-	TODO: check
+	- guzzle <unfixed>
+	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-25mq-v84q-4j7r
+	NOTE: https://github.com/guzzle/guzzle/commit/1dd98b0564cb3f6bd16ce683cb755f94c10fbd82 (7.4.5)
 CVE-2022-31089 (Parse Server is an open source backend that can be deployed to any inf ...)
 	TODO: check
 CVE-2022-31088 (LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f47ed3488b716f356edfb4e77f898635b81fb0a0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f47ed3488b716f356edfb4e77f898635b81fb0a0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220628/4b3c01bb/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list