[Git][security-tracker-team/security-tracker][master] Added a note to rabbitmq-server.

Ola Lundqvist (@opal) opal at debian.org
Tue Nov 1 22:46:33 GMT 2022



Ola Lundqvist pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7d3dc636 by Ola Lundqvist at 2022-11-01T23:45:24+01:00
Added a note to rabbitmq-server.

- - - - -


1 changed file:

- data/dla-needed.txt


Changes:

=====================================
data/dla-needed.txt
=====================================
@@ -207,6 +207,7 @@ rabbitmq-server
   NOTE: 20221031: Programming language: Erlang.
   NOTE: 20221031: New configuration option. Should be studied further..
   NOTE: 20221031: Potentially the outcome is to ignore the issue..
+  NOTE: 20221101: The package is not vulnerable to that URLs can be decoded because they are not even encoded. That is most likely a much worse problem, but requires some more investigations. Possible a new CVE is needed for that.
 --
 rails (Abhijith PA)
   NOTE: 20220909: Regression on 2:5.2.2.1+dfsg-1+deb10u4 (abhijith)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d3dc6369d7cf98ce3cbb13738250cf8ce3f2815

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d3dc6369d7cf98ce3cbb13738250cf8ce3f2815
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221101/413fed2a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list