- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Yadd
- Date:
- 2022-07-09 10:51:36 UTC
- Severity:
- normal
- Tags:
[ Reason ] node-mermaid is vulnerable to XSS attack (CVE-2021-23648) [ Impact ] medium vulnerability [ Tests ] Test passed, new upstream test not applicable here [ Risks ] Low risk, patch is trivial [ Checklist ] [X] *all* changes are documented in the d/changelog [X] I reviewed all changes and I approve them [X] attach debdiff against the package in (old)stable [X] the issue is verified as fixed in unstable [ Changes ] Decode HTML entities before parsing URLs Cheers, Yadd
Control: tags -1 + confirmed Please go ahead. Regards, Adam
package release.debian.org tags 1008045 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: node-mermaid Version: 8.7.0+ds+~cs27.17.17-3+deb11u1 Explanation: fix cross-site scripting issue [CVE-2021-23648]
package release.debian.org tags 1008045 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: node-mermaid Version: 8.7.0+ds+~cs27.17.17-3+deb11u1 Explanation: fix cross-site scripting issue [CVE-2021-23648]
Hi Yadd, Could you fix as well CVE-2021-43861 in the next point release? Should be then on top of the already uploaded +deb11u1. Regards, Salvatore
Hi, done (8.7.0+ds+~cs27.17.17-3+deb11u2), just pushed to Bullseye queue Regards, Yadd
package release.debian.org tags 1008045 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: node-mermaid Version: 8.7.0+ds+~cs27.17.17-3+deb11u2 Explanation: fix cross-site scripting issue [CVE-2021-43861]
package release.debian.org tags 1008045 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: node-mermaid Version: 8.7.0+ds+~cs27.17.17-3+deb11u2 Explanation: fix cross-site scripting issue [CVE-2021-43861]
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam