summaryrefslogtreecommitdiffstats
path: root/data/CVE/list.2015
diff options
context:
space:
mode:
authorMoritz Mühlenhoff <jmm@debian.org>2020-10-29 19:52:21 +0100
committerMoritz Mühlenhoff <jmm@debian.org>2020-10-29 19:52:21 +0100
commit8cb5864a2f8f5aca341f41a0d6b0bac0333d3293 (patch)
tree6e6e8255c9f9272f565fd0bae4dde7977e05a3d4 /data/CVE/list.2015
parent2e1db929b0e6a72e1d83466eec4f4e37df8626a6 (diff)
various bugs
Diffstat (limited to 'data/CVE/list.2015')
-rw-r--r--data/CVE/list.20152
1 files changed, 1 insertions, 1 deletions
diff --git a/data/CVE/list.2015 b/data/CVE/list.2015
index 024193c2e1..420e18cc7a 100644
--- a/data/CVE/list.2015
+++ b/data/CVE/list.2015
@@ -559,7 +559,7 @@ CVE-2015-9286 (Controllers.outgoing in controllers/index.js in NodeBB before 0.7
CVE-2015-9285 (esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI. ...)
NOT-FOR-US: esoTalk
CVE-2015-9284 (The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vuln ...)
- - ruby-omniauth <unfixed>
+ - ruby-omniauth <unfixed> (bug #973384)
[buster] - ruby-omniauth <no-dsa> (Minor issue)
[stretch] - ruby-omniauth <no-dsa> (Minor issue)
[jessie] - ruby-omniauth <no-dsa> (Fix is in additional gem and needs CSRF protection in apps)

© 2014-2024 Faster IT GmbH | imprint | privacy policy