Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits: ecbd44a4 by Moritz Muehlenhoff at 2024-02-28T11:27:49+01:00 new scrapy issue - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -33,7 +33,11 @@ CVE-2024-1943 (The Yuki theme for WordPress is vulnerable to Cross-Site Request CVE-2024-1932 (Unrestricted Upload of File with Dangerous Type in freescout-helpdesk/ ...) NOT-FOR-US: freescout-helpdesk CVE-2024-1892 (Parts of the Scrapy API were found to be vulnerable to a ReDoS attack. ...) - TODO: check + - python-scrapy <unfixed> + [bookworm] - python-scrapy <no-dsa> (Minor issue) + [bullseye] - python-scrapy <no-dsa> (Minor issue) + NOTE: https://huntr.com/bounties/271f94f2-1e05-4616-ac43-41752389e26b/ + NOTE: https://github.com/scrapy/scrapy/commit/479619b340f197a8f24c5db45bc068fb8755f2c5 (2.11.1) CVE-2024-1866 REJECTED CVE-2024-1865 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ecbd44a4c8474490cc6ae24e97413d379070d144 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ecbd44a4c8474490cc6ae24e97413d379070d144 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits