Bug#985220: velocity: CVE-2020-13936

Andreas Beckmann anbe at debian.org
Wed May 5 21:04:46 BST 2021


Followup-For: Bug #985220

Hi,

CVE-2020-13936 is fixed in stretch-security but not buster, making
upgrades difficult since stetch-security has a newer version than buster.
Please upload the fix to buster, too.

 velocity | 1.7-4        | jessie           | source, all
 velocity | 1.7-5        | stretch          | source, all
 velocity | 1.7-5        | buster           | source, all
 velocity | 1.7-5+deb9u1 | stretch-security | source, all
 velocity | 1.7-6        | bullseye         | source, all
 velocity | 1.7-6        | sid              | source, all

Andreas



More information about the pkg-java-maintainers mailing list