Bug#969366: buster-pu: package node-url-parse/1.2.0-2+deb10u1

2020-09-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2020-09-01 at 13:01 +0200, Xavier Guimard wrote: > Insufficient validation and sanitization of user input exists in url- > parse npm package version 1.4.4 and earlier may allow attacker to > bypass security checks. > Please go ahead. Regards, Adam

Bug#969366: buster-pu: package node-url-parse/1.2.0-2+deb10u1

2020-09-01 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu [ Reason ] Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks. [ Impact ]