Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
bf0bb595 by Salvatore Bonaccorso at 2023-03-14T21:56:54+01:00
Track proposed node-webpack update via bullseye-pu
- - - - -
2 changed files:
- data/CVE/list
- data/next-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -575,6 +575,7 @@ CVE-2023-28155
RESERVED
CVE-2023-28154 (Webpack 5 before 5.76.0 does not avoid cross-realm object
access. Impo ...)
- node-webpack 5.76.1+dfsg1+~cs17.16.16-1 (bug #1032904)
+ [bullseye] - node-webpack <no-dsa> (Minor issue)
NOTE: https://github.com/webpack/webpack/pull/16500
NOTE: Merge commit:
https://github.com/webpack/webpack/commit/4b4ca3bb53f36a5b8fc6bc1bd976ed7af161bd80
(v5.76.0)
CVE-2023-1363 (A vulnerability, which was classified as problematic, was found
in Sou ...)
=====================================
data/next-point-update.txt
=====================================
@@ -146,3 +146,5 @@ CVE-2022-21222
[bullseye] - node-css-what 4.0.0-3+deb11u1
CVE-2021-33587
[bullseye] - node-css-what 4.0.0-3+deb11u1
+CVE-2023-28154
+ [bullseye] - node-webpack 4.43.0-6+deb11u1
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf0bb595d0b6f59c1c7ef6f74e4e2767ead8e31b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf0bb595d0b6f59c1c7ef6f74e4e2767ead8e31b
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits