- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Yadd
- Date:
- 2022-07-09 10:51:46 UTC
- Severity:
- normal
- Tags:
[ Reason ] node-url-parse is vulnerable to an authorization Bypass Through User-Controlled (CVE-2022-0686). [ Impact ] medium vulnerability [ Tests ] Test updated, passed [ Risks ] Low risk, patch is trivial and new test passed [ Checklist ] [X] *all* changes are documented in the d/changelog [X] I reviewed all changes and I approve them [X] attach debdiff against the package in (old)stable [X] the issue is verified as fixed in unstable [ Changes ] Better checks. Cheers, Yadd
Am Wed, Mar 23, 2022 at 02:25:26PM +0100 schrieb Yadd:
If we're doing an update, we could also include a fix for CVE-2022-0691?
Cheers,
Moritz
Hi, done, here is the new debdiff (including new test) Cheers, Yadd
Control: tags -1 + confirmed Please go ahead. Regards, Adam
package release.debian.org tags 1008168 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: node-url-parse Version: 1.5.3-1+deb11u1 Explanation: fix authentication bypass issues [CVE-2022-0686 CVE-2022-0691]
package release.debian.org tags 1008168 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: node-url-parse Version: 1.5.3-1+deb11u1 Explanation: fix authentication bypass issues [CVE-2022-0686 CVE-2022-0691]
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam