summaryrefslogtreecommitdiffstats
path: root/data
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2020-12-28 07:11:12 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2020-12-28 07:11:12 +0100
commit336968cafc11de3fce7186b9addf74f132673aef (patch)
tree524611a8d5eaef686a3f72dd05137b251369701f /data
parent94078165fc06042272f329804090019c933fd9cb (diff)
Reference upstream commits for CVE-2020-35730
Diffstat (limited to 'data')
-rw-r--r--data/CVE/list3
1 files changed, 3 insertions, 0 deletions
diff --git a/data/CVE/list b/data/CVE/list
index 71d9bb0164..7e7dd2e0d5 100644
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -13,6 +13,9 @@ CVE-2020-35731
CVE-2020-35730 [Stored cross-site scripting (XSS) via HTML or plain text messages with malicious content]
RESERVED
- roundcube 1.4.10+dfsg.1-1 (bug #978491)
+ NOTE: https://github.com/roundcube/roundcubemail/commit/0bceba301aa621ecc0263eac17beee2a4cef0c6d (1.4.10)
+ NOTE: https://github.com/roundcube/roundcubemail/commit/a06ec1dcf9c972d302b16e1ac6aa079a4f6a1c3e (1.3.16)
+ NOTE: https://github.com/roundcube/roundcubemail/commit/47e4d44f62ea16f923761d57f1773a66d51afad4 (1.2.13)
CVE-2020-35729 (KLog Server 2.4.1 allows OS command injection via shell metacharacters ...)
NOT-FOR-US: KLog Server
CVE-2020-35728 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...)

© 2014-2024 Faster IT GmbH | imprint | privacy policy