From 06342afe94034dd6d5274fc0812aa8f71bae3da2 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Sun, 2 Jan 2022 16:07:45 +0100 Subject: Add Debian bug reference for CVE-2021-43617 --- data/CVE/list | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/CVE/list b/data/CVE/list index ef6cf94d24..3fbcd3c6f0 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -8264,7 +8264,7 @@ CVE-2021-43618 (GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 ha NOTE: https://gmplib.org/list-archives/gmp-bugs/2021-September/005077.html NOTE: https://gmplib.org/repo/gmp-6.2/rev/561a9c25298e CVE-2021-43617 (Laravel Framework through 8.70.2 does not sufficiently block the uploa ...) - - php-laravel-framework 6.20.14+dfsg-3 + - php-laravel-framework 6.20.14+dfsg-3 (bug #1002728) [bullseye] - php-laravel-framework (Can be fixed via point release) NOTE: https://hosein-vita.medium.com/laravel-8-x-image-upload-bypass-zero-day-852bd806019b CVE-2021-3957 (kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) ...) -- cgit v1.2.3