#1008168 bullseye-pu: package node-url-parse/1.5.3-1+deb11u1

#1008168#5
Date:
2022-03-23 13:25:26 UTC
From:
To:
[ Reason ]
node-url-parse is vulnerable to an authorization Bypass Through
User-Controlled (CVE-2022-0686).

[ Impact ]
medium vulnerability

[ Tests ]
Test updated, passed

[ Risks ]
Low risk, patch is trivial and new test passed

[ Checklist ]
  [X] *all* changes are documented in the d/changelog
  [X] I reviewed all changes and I approve them
  [X] attach debdiff against the package in (old)stable
  [X] the issue is verified as fixed in unstable

[ Changes ]
Better checks.

Cheers,
Yadd

#1008168#10
Date:
2022-03-24 14:12:37 UTC
From:
To:
Am Wed, Mar 23, 2022 at 02:25:26PM +0100 schrieb Yadd:

If we're doing an update, we could also include a fix for CVE-2022-0691?

Cheers,
        Moritz

#1008168#15
Date:
2022-04-11 14:17:25 UTC
From:
To:
Hi,

done, here is the new debdiff (including new test)

Cheers,
Yadd

#1008168#20
Date:
2022-05-28 20:12:31 UTC
From:
To:
Control: tags -1 + confirmed

Please go ahead.

Regards,

Adam

#1008168#27
Date:
2022-05-29 18:01:45 UTC
From:
To:
package release.debian.org
tags 1008168 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: node-url-parse
Version: 1.5.3-1+deb11u1

Explanation: fix authentication bypass issues [CVE-2022-0686 CVE-2022-0691]

#1008168#32
Date:
2022-05-29 18:01:45 UTC
From:
To:
package release.debian.org
tags 1008168 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: node-url-parse
Version: 1.5.3-1+deb11u1

Explanation: fix authentication bypass issues [CVE-2022-0686 CVE-2022-0691]

#1008168#37
Date:
2022-07-09 10:47:43 UTC
From:
To:
(re-sending with fixed bug numbers)

Hi,

The updates discussed in these bugs were included in today's bullseye
point release.

Regards,

Adam