[Git][security-tracker-team/security-tracker][master] CVE-2021-3020/crmsh 4.3.1

Neil Williams (@codehelp) codehelp at debian.org
Fri Sep 2 08:40:55 BST 2022



Neil Williams pushed to branch master at Debian Security Tracker / security-tracker


Commits:
24ec2bd1 by Neil Williams at 2022-09-02T08:40:07+01:00
CVE-2021-3020/crmsh 4.3.1

Vulnerable in bullseye

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -114046,7 +114046,13 @@ CVE-2021-3022 (An issue was discovered on LG mobile devices with Android OS 10 s
 CVE-2021-3021 (ISPConfig before 3.2.2 allows SQL injection. ...)
 	NOT-FOR-US: ISPConfig
 CVE-2021-3020 (An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) throu ...)
-	TODO: check
+	- crmsh 4.3.1
+	[bullseye] - crmsh <unfixed>
+	[buster] - crmsh <not-affected> (Vulnerable code introduced later)
+	NOTE: https://github.com/ClusterLabs/crmsh/commit/c538024b8ebd138dc373b005189471d9b77e9c82 (4.3.1)
+	NOTE: Introduced in https://github.com/ClusterLabs/crmsh/commit/086a8a9e995eae1041a25d8aa27da4b3da5e1236 (4.2.1)
+	NOTE: https://github.com/ClusterLabs/hawk/releases
+	NOTE: https://bugzilla.suse.com/show_bug.cgi?id=1180571 (private)
 CVE-2021-22685
 	RESERVED
 CVE-2021-22684 (Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24ec2bd174972d723fb161395cb8a28d6adc7c10

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24ec2bd174972d723fb161395cb8a28d6adc7c10
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220902/1ca52923/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list