From ab63ee5007f7aa757a61f65dfa2498ba1d35e544 Mon Sep 17 00:00:00 2001 From: Abhijith PA Date: Tue, 20 Oct 2020 00:12:16 +0530 Subject: Mark CVE-2020-17480 as no-dsa, there are other workarounds available --- data/CVE/list.2020 | 1 + 1 file changed, 1 insertion(+) diff --git a/data/CVE/list.2020 b/data/CVE/list.2020 index 81d7b0aa06..bb99b275ab 100644 --- a/data/CVE/list.2020 +++ b/data/CVE/list.2020 @@ -19949,6 +19949,7 @@ CVE-2020-17481 CVE-2020-17480 (TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parse ...) - tinymce [buster] - tinymce (Minor issue) + [stretch] - tinymce (Minor issue) NOTE: https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95 CVE-2020-17479 (jpv (aka Json Pattern Validator) before 2.2.2 does not properly valida ...) NOT-FOR-US: jpv -- cgit v1.2.3