Bug#961298: jodd: CVE-2018-21234: Potential vulnerability in JSON deserialization

2021-03-01 Thread Salvatore Bonaccorso
Hi Emmanuel, On Sat, May 30, 2020 at 02:50:32PM +0200, Emmanuel Bourg wrote: > Control: severity -1 important > > Le 22/05/2020 à 22:51, Salvatore Bonaccorso a écrit : > > > The following vulnerability was published for jodd. I'm filling it as > > RC severity since altough one might dispute the

Bug#961298: jodd: CVE-2018-21234: Potential vulnerability in JSON deserialization

2020-05-30 Thread Emmanuel Bourg
Control: severity -1 important Le 22/05/2020 à 22:51, Salvatore Bonaccorso a écrit : > The following vulnerability was published for jodd. I'm filling it as > RC severity since altough one might dispute the severity for the issue > itself, it looks that in Debian there was ever only one upload

Bug#961298: jodd: CVE-2018-21234: Potential vulnerability in JSON deserialization

2020-05-22 Thread Salvatore Bonaccorso
Source: jodd Version: 3.8.6-1 Severity: grave Tags: security upstream Justification: user security hole Forwarded: https://github.com/oblac/jodd/issues/628 Hi, The following vulnerability was published for jodd. I'm filling it as RC severity since altough one might dispute the severity for the