diff options
author | Kai Knoblich <kai@FreeBSD.org> | 2019-11-22 19:15:09 +0800 |
---|---|---|
committer | Kai Knoblich <kai@FreeBSD.org> | 2019-11-22 19:15:09 +0800 |
commit | 755123defe9ad5d6e13872304640dcf6d0b1f701 (patch) | |
tree | a484ad93d19f39aca604053da13d3dabbecd2f94 /security | |
parent | 9e0d3a92b243b16b923223feb1bda329d2d561b6 (diff) | |
download | freebsd-ports-gnome-755123defe9ad5d6e13872304640dcf6d0b1f701.tar.gz freebsd-ports-gnome-755123defe9ad5d6e13872304640dcf6d0b1f701.tar.zst freebsd-ports-gnome-755123defe9ad5d6e13872304640dcf6d0b1f701.zip |
security/vuxml: Document www/gitea issues
PR: 241981
Submitted by: Nils Johannsen <nilsjohannsen@gmx.de> (based on)
Approved by: stb@lassitu.de (maintainer)
Diffstat (limited to 'security')
-rw-r--r-- | security/vuxml/vuln.xml | 33 |
1 files changed, 33 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 5a7823a65b4d..eeb86f568188 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,39 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="b12a341a-0932-11ea-bf09-080027e0baa0"> + <topic>gitea -- multiple vulnerabilities</topic> + <affects> + <package> + <name>gitea</name> + <range><lt>1.9.10</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>The Gitea Team reports:</p> + <blockquote cite="https://blog.gitea.io/2019/11/gitea-1.10.0-is-released/"> + <p>This release contains five security fixes, so we recommend updating:</p> + <ul> + <li>Fix issue with user.fullname</li> + <li>Ignore mentions for users with no access</li> + <li>Be more strict with git arguments</li> + <li>Extract the username and password from the mirror url</li> + <li>Reserve .well-known username</li> + </ul> + </blockquote> + </body> + </description> + <references> + <url>https://blog.gitea.io/2019/11/gitea-1.10.0-is-released/</url> + <freebsdpr>ports/241981</freebsdpr> + </references> + <dates> + <discovery>2019-11-17</discovery> + <entry>2019-11-22</entry> + </dates> + </vuln> + <vuln vid="94c6951a-0d04-11ea-87ca-001999f8d30b"> <topic>asterisk -- Re-invite with T.38 and malformed SDP causes crash</topic> <affects> |