From 97a03ca75233bff7e39eb228c969d733aec11cad Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Mon, 21 Feb 2022 21:02:24 +0100 Subject: Track fixed version for CVE-2022-0686/node-url-parse via unstable --- data/CVE/list.2022 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/CVE/list.2022 b/data/CVE/list.2022 index 0570c2b0e5..41d446fa17 100644 --- a/data/CVE/list.2022 +++ b/data/CVE/list.2022 @@ -487,7 +487,7 @@ CVE-2022-0688 (Business Logic Errors in Packagist microweber/microweber prior to CVE-2022-0687 RESERVED CVE-2022-0686 (Authorization Bypass Through User-Controlled Key in NPM url-parse prio ...) - - node-url-parse + - node-url-parse 1.5.9+~1.4.8-1 NOTE: https://huntr.dev/bounties/55fd06cd-9054-4d80-83be-eb5a454be78c NOTE: https://github.com/unshiftio/url-parse/commit/d5c64791ef496ca5459ae7f2176a31ea53b127e5 (1.5.8) CVE-2022-0685 (Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior ...) -- cgit v1.2.3