Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
43adcae4 by Salvatore Bonaccorso at 2019-12-20T12:37:44Z
Update information on CVE-2019-3866

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -52748,11 +52748,17 @@ CVE-2019-3867
        NOT-FOR-US: OpenShift (web-cosnole issue specific to OpenShift only)
 CVE-2019-3866 (An information-exposure vulnerability was discovered where 
openstack-m ...)
        - python-oslo.utils <unfixed> (low; bug #946060)
-       [stretch] - python-oslo.utils <not-affected> (regex pattern rewrite)
        [jessie] - python-oslo.utils <not-affected> (regex pattern rewrite)
+       - python-mistral-lib <unfixed>
+       - mistral 5.1.0-2
+       NOTE: In mistral/5.0.0 the problematic code was moved to the python 
library.
+       NOTE: To be apply the fixes in mistral/python-mistral-lib as 
pre-requiste the
+       NOTE: python-oslo.utils package needs an update.
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1768731
        NOTE: https://bugs.launchpad.net/tripleo/+bug/1850843
        NOTE: 
https://opendev.org/openstack/oslo.utils/commit/b41268417cecb12d1d5955ee3107067edf050221
+       NOTE: Patch for Pike and newer: 
https://launchpadlibrarian.net/449473654/0001-Ensure-we-mask-sensitive-data-from-Mistral-Action-lo.patch
+       NOTE: Patch for Pike and newer: 
https://launchpadlibrarian.net/449472809/0001-Ensure-we-mask-sensitive-data-from-Mistral-Action-lo.patch
 CVE-2019-3865
        RESERVED
        NOT-FOR-US: Quay



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/43adcae419395c70399fecf54c93a98b8e852753

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/commit/43adcae419395c70399fecf54c93a98b8e852753
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to