From 7e441e8685819e967648059f620b871014a09929 Mon Sep 17 00:00:00 2001 From: Abhijith PA Date: Tue, 20 Oct 2020 22:57:34 +0530 Subject: Seems it is not reproducible with PoC https://labs.bishopfox.com/advisories/tinymce-version-5.2.1 Marked as not-affected fot stretch --- data/CVE/list | 1 + 1 file changed, 1 insertion(+) diff --git a/data/CVE/list b/data/CVE/list index 54a0e7e826..4fce35bc56 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -32416,6 +32416,7 @@ CVE-2020-12649 (Gurbalib through 2020-04-30 allows lib/cmds/player/help.c direct CVE-2020-12648 (A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlie ...) - tinymce [buster] - tinymce (Minor issue) + [stretch] - tinymce (Vulnerable code not present and not reproducible) NOTE: https://labs.bishopfox.com/advisories/tinymce-version-5.2.1 CVE-2020-12647 (Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 59.1a.9, and 6 ...) NOT-FOR-US: Unisys ALGOL Compiler -- cgit v1.2.3