diff options
author | Salvatore Bonaccorso <carnil@debian.org> | 2020-12-28 07:11:12 +0100 |
---|---|---|
committer | Salvatore Bonaccorso <carnil@debian.org> | 2020-12-28 07:11:12 +0100 |
commit | 336968cafc11de3fce7186b9addf74f132673aef (patch) | |
tree | 524611a8d5eaef686a3f72dd05137b251369701f /data | |
parent | 94078165fc06042272f329804090019c933fd9cb (diff) |
Reference upstream commits for CVE-2020-35730
Diffstat (limited to 'data')
-rw-r--r-- | data/CVE/list | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/data/CVE/list b/data/CVE/list index 71d9bb0164..7e7dd2e0d5 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -13,6 +13,9 @@ CVE-2020-35731 CVE-2020-35730 [Stored cross-site scripting (XSS) via HTML or plain text messages with malicious content] RESERVED - roundcube 1.4.10+dfsg.1-1 (bug #978491) + NOTE: https://github.com/roundcube/roundcubemail/commit/0bceba301aa621ecc0263eac17beee2a4cef0c6d (1.4.10) + NOTE: https://github.com/roundcube/roundcubemail/commit/a06ec1dcf9c972d302b16e1ac6aa079a4f6a1c3e (1.3.16) + NOTE: https://github.com/roundcube/roundcubemail/commit/47e4d44f62ea16f923761d57f1773a66d51afad4 (1.2.13) CVE-2020-35729 (KLog Server 2.4.1 allows OS command injection via shell metacharacters ...) NOT-FOR-US: KLog Server CVE-2020-35728 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...) |