Bug#1059296: hamster-time-tracker: CVE-2023-36250

2023-12-24 Thread Matthijs Kooijman
forwarded 1059296 https://github.com/projecthamster/hamster/issues/750 thanks Hi Moritz, Thanks for bringing this to attention, this was not reported upstream yet. > https://github.com/BrunoTeixeira1996/CVE-2023-36250/blob/main/README.md > sounds a little bogus, I don't see how this crosses any

Bug#1059296: hamster-time-tracker: CVE-2023-36250

2023-12-22 Thread Moritz Mühlenhoff
Source: hamster-time-tracker X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for hamster-time-tracker. CVE-2023-36250[0]: | CSV Injection vulnerability in GNOME time tracker version 3.0.2, | allows local attackers to