Bug#988804: prometheus: CVE-2021-29622

2021-05-19 Thread Salvatore Bonaccorso
Hi Martina, On Thu, May 20, 2021 at 06:16:34AM +0100, Martina Ferrari wrote: > On 20/05/2021 05:11, Salvatore Bonaccorso wrote: > > > Thanks, so I have to assume we are protected since 63d6cb569d4e > > ("Refresh patches and patch out react-app URL handlers") in the > > packaging repository,

Bug#988804: prometheus: CVE-2021-29622

2021-05-19 Thread Martina Ferrari
On 20/05/2021 05:11, Salvatore Bonaccorso wrote: Thanks, so I have to assume we are protected since 63d6cb569d4e ("Refresh patches and patch out react-app URL handlers") in the packaging repository, which would be in debian/2.15.2+ds-1. Is this correct? To be precise, that commit patched out

Bug#988804: prometheus: CVE-2021-29622

2021-05-19 Thread Salvatore Bonaccorso
Hi Martina, On Wed, May 19, 2021 at 11:36:01PM +0100, Martina Ferrari wrote: > Hi Salvatore, > > On 19/05/2021 19:40, Salvatore Bonaccorso wrote: > > > > The following vulnerability was published for prometheus. > > > > CVE-2021-29622[0]: > > | Open Redirect under the /new endpoint > > > > If

Bug#988804: prometheus: CVE-2021-29622

2021-05-19 Thread Salvatore Bonaccorso
Source: prometheus Version: 2.24.1+ds-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for prometheus. CVE-2021-29622[0]: | Open Redirect under the /new endpoint If