Bug#969362: python-flask-cors: CVE-2020-25032

2020-10-19 Thread Salvatore Bonaccorso
Hi Bastian, On Wed, Oct 14, 2020 at 05:39:00PM +0200, Salvatore Bonaccorso wrote: > Hi Bastian, > > On Tue, Oct 13, 2020 at 11:36:40PM +0200, Bastian Germann wrote: > > Hi Salvatore, > > > > Thanks for your hints. > > > > Am 10.10.20 um 23:02 schrieb Salvatore Bonaccorso: > > > Hi Bastian, > >

Bug#969362: python-flask-cors: CVE-2020-25032

2020-10-14 Thread Salvatore Bonaccorso
Hi Bastian, On Tue, Oct 13, 2020 at 11:36:40PM +0200, Bastian Germann wrote: > Hi Salvatore, > > Thanks for your hints. > > Am 10.10.20 um 23:02 schrieb Salvatore Bonaccorso: > > Hi Bastian, > > > > [Please do send such requests always to team@s.d.o, dev-ref gives as > > well some further

Bug#969362: python-flask-cors: CVE-2020-25032

2020-10-13 Thread Bastian Germann
Hi Salvatore, Thanks for your hints. Am 10.10.20 um 23:02 schrieb Salvatore Bonaccorso: > Hi Bastian, > > [Please do send such requests always to team@s.d.o, dev-ref gives as > well some further hints at >

Bug#969362: python-flask-cors: CVE-2020-25032

2020-10-10 Thread Salvatore Bonaccorso
Hi Bastian, [Please do send such requests always to team@s.d.o, dev-ref gives as well some further hints at https://www.debian.org/doc/manuals/developers-reference/pkgs.en.html#handling-security-related-bugs] On Thu, Oct 08, 2020 at 04:25:55PM +0200, Bastian Germann wrote: > On Tue, 01 Sep 2020

Bug#969362: python-flask-cors: CVE-2020-25032

2020-10-08 Thread Bastian Germann
On Tue, 01 Sep 2020 10:51:48 +0200 Salvatore Bonaccorso wrote: > The following vulnerability was published for python-flask-cors. > > CVE-2020-25032[0]: > | An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) > | before 3.0.9. It allows ../ directory traversal to access private

Bug#969362: python-flask-cors: CVE-2020-25032

2020-09-01 Thread Salvatore Bonaccorso
Source: python-flask-cors Version: 3.0.8-2 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: found -1 3.0.7-1 Hi, The following vulnerability was published for python-flask-cors. CVE-2020-25032[0]: | An issue was discovered in Flask-CORS