[Git][security-tracker-team/security-tracker][master] Add information for CVE-2021-33503

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Oct 8 15:16:11 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
61d013ae by Salvatore Bonaccorso at 2023-10-08T16:15:17+02:00
Add information for CVE-2021-33503

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -165913,7 +165913,8 @@ CVE-2021-33503 (An issue was discovered in urllib3 before 1.26.5. When provided
 	[buster] - python-urllib3 <not-affected> (Vulnerable code introduced later)
 	[stretch] - python-urllib3 <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/advisories/GHSA-q2q7-5pp4-w6pg
-	NOTE: https://github.com/urllib3/urllib3/commit/2d4a3fee6de2fa45eb82169361918f759269b4ec
+	NOTE: Introduced around: https://github.com/urllib3/urllib3/commit/5b047b645f5f93900d5e2fc31230848c25eb1f5f (1.25.4)
+	NOTE: Fixed by: https://github.com/urllib3/urllib3/commit/2d4a3fee6de2fa45eb82169361918f759269b4ec (1.26.5)
 CVE-2021-33502 (The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x befo ...)
 	- node-got 11.8.1+~cs53.13.17-3 (bug #989258)
 	[buster] - node-got <not-affected> (Vulnerable code introduced later)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/61d013ae08f74f7a013c0e23e478b56d3ca33eaf

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/61d013ae08f74f7a013c0e23e478b56d3ca33eaf
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231008/766f1a5a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list