From 001ff21cb8880a3ab32219c25056304aa1a56d5c Mon Sep 17 00:00:00 2001 From: Thorsten Alteholz Date: Sat, 27 Nov 2021 00:30:49 +0100 Subject: mark CVE-2020-27511 as no-dsa for Stretch --- data/CVE/list.2020 | 1 + 1 file changed, 1 insertion(+) diff --git a/data/CVE/list.2020 b/data/CVE/list.2020 index 498a1b39db..628da07fe6 100644 --- a/data/CVE/list.2020 +++ b/data/CVE/list.2020 @@ -8797,6 +8797,7 @@ CVE-2020-27512 CVE-2020-27511 (An issue was discovered in the stripTags and unescapeHTML components i ...) - prototypejs (bug #991898) [bullseye] - prototypejs (Minor issue) + [stretch] - prototypejs (Minor issue) NOTE: https://github.com/prototypejs/prototype/blame/dee2f7d8611248abce81287e1be4156011953c90/src/prototype/lang/string.js#L283 NOTE: https://github.com/yetingli/PoCs/blob/main/CVE-2020-27511/Prototype.md NOTE: CVE mentions newer version but vulnerable code exists in older versions too -- cgit v1.2.3