- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Yadd
- Date:
- 2022-07-09 10:53:22 UTC
- Severity:
- normal
- Tags:
[ Reason ] node-got allows redirection to unix sockets (#1013264, CVE-2022-33987) [ Impact ] Medium vulnerability: a remote host can redirect a node-got request to a Unix socket [ Tests ] Sadly test aren't enabled: ava was introduced earlier in Debian [ Risks ] Low risk: * patch is trivial * package is built from TypeScript, then tsc compiler checks for a lot of errors [ Checklist ] [X] *all* changes are documented in the d/changelog [X] I reviewed all changes and I approve them [X] attach debdiff against the package in (old)stable [X] the issue is verified as fixed in unstable [ Changes ] Just reject URL starting with "unix:" if original request wasn't a "unix:" request. Note that I had to add a typescript change: one ignored error is no more an error. Regards, Yadd
Control: tags -1 + confirmed Please go ahead. Regards, Adam
package release.debian.org tags 1014054 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: node-got Version: 11.8.1+~cs53.13.17-3+deb11u1 Explanation: don't allow redirection to Unix socket [CVE-2022-33987]
package release.debian.org tags 1014054 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: node-got Version: 11.8.1+~cs53.13.17-3+deb11u1 Explanation: don't allow redirection to Unix socket [CVE-2022-33987]
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam