Abhijith PA pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a1e7756f by Abhijith PA at 2020-04-02T12:09:56+05:30
CVE-2020-1771 associated with JS injection to customer address book
which not present in  version 3.3.18-1+deb8u14

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -24035,6 +24035,7 @@ CVE-2020-1771 (Attacker is able craft an article with a 
link to the customer add
        - otrs2 6.0.27-1
        [buster] - otrs2 <no-dsa> (Non-free not supported)
        [stretch] - otrs2 <no-dsa> (Non-free not supported)
+       [jessie] - otrs2 <not-affected> (Vulnerable code introduced in later 
version)
        NOTE: https://otrs.com/release-notes/otrs-security-advisory-2020-08/
        NOTE: Fixed in 7.0.16, 6.0.27
        NOTE: 
https://github.com/OTRS/otrs/commit/2576830053f70a3a9251558e55f34843dec61aa2



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a1e7756fa80b221c17b2f36dc2671eaf2e79bffe

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a1e7756fa80b221c17b2f36dc2671eaf2e79bffe
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to