Bastien Roucariès pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
93043d1c by Bastien Roucariès at 2025-04-26T00:02:24+02:00
Add bullseye anotation for CVE-2025-3573
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3714,9 +3714,11 @@ CVE-2025-3576 (A vulnerability in the MIT Kerberos
implementation allows GSSAPI-
NOTE: explicitly configured with the new allow_rc4 or allow_des3
variables respectively.
CVE-2025-3573 (Versions of the package jquery-validation before 1.20.0 are
vulnerable ...)
- civicrm <unfixed> (bug #1103445)
+ [bullseye] - civicrm <postponed> (Minor Issue; XSS)
- kalkun <unfixed> (bug #1104134)
- znuny <unfixed> (bug #1104135)
- phpmyadmin <unfixed> (bug #1104136)
+ [bullseye] - phpmyadmin <postponed> (Minor Issue; barely an issue in
the phpmyadmin package XSS)
NOTE: https://github.com/jquery-validation/jquery-validation/pull/2462
NOTE:
https://github.com/jquery-validation/jquery-validation/commit/7a490d8f39bd988027568ddcf51755e1f4688902
NOTE: civicrm embedds jquery-validation
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/93043d1ca1f6ba3f93129482abdb961cb2ff2ebc
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/93043d1ca1f6ba3f93129482abdb961cb2ff2ebc
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits