Your message dated Thu, 23 Feb 2023 21:21:58 +0100
with message-id <Y/[email protected]>
and subject line Re: Bug#1026050: jquery-minicolors: CVE-2021-4243
has caused the Debian Bug report #1026050,
regarding jquery-minicolors: CVE-2021-4243
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1026050: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1026050
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: jquery-minicolors
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for jquery-minicolors.

CVE-2021-4243[0]:
| A vulnerability was found in claviska jquery-minicolors up to 2.3.5.
| It has been rated as problematic. Affected by this issue is some
| unknown functionality of the file jquery.minicolors.js. The
| manipulation leads to cross site scripting. The attack may be launched
| remotely. Upgrading to version 2.3.6 is able to address this issue.
| The name of the patch is ef134824a7f4110ada53ea6c173111a4fa2f48f3. It
| is recommended to upgrade the affected component. VDB-215306 is the
| identifier assigned to this vulnerability.

https://github.com/claviska/jquery-minicolors/releases/tag/2.3.6
https://github.com/claviska/jquery-minicolors/commit/ef134824a7f4110ada53ea6c173111a4fa2f48f3

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-4243
    https://www.cve.org/CVERecord?id=CVE-2021-4243

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Hi,

On Tue, Dec 13, 2022 at 08:04:38PM +0100, Moritz Mühlenhoff wrote:
> Source: jquery-minicolors
> X-Debbugs-CC: [email protected]
> Severity: important
> Tags: security
> 
> Hi,
> 
> The following vulnerability was published for jquery-minicolors.
> 
> CVE-2021-4243[0]:
> | A vulnerability was found in claviska jquery-minicolors up to 2.3.5.
> | It has been rated as problematic. Affected by this issue is some
> | unknown functionality of the file jquery.minicolors.js. The
> | manipulation leads to cross site scripting. The attack may be launched
> | remotely. Upgrading to version 2.3.6 is able to address this issue.
> | The name of the patch is ef134824a7f4110ada53ea6c173111a4fa2f48f3. It
> | is recommended to upgrade the affected component. VDB-215306 is the
> | identifier assigned to this vulnerability.

Closing, as CVE-2021-4243 was rejected in favour of CVE-2021-32850,
#1031791.

Regards,
Salvatore

--- End Message ---

Reply via email to