Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 99b9bd08 by Salvatore Bonaccorso at 2025-01-21T21:44:06+01:00 Add CVE-2025-22150/node-undici - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -103,7 +103,11 @@ CVE-2025-22267 (Improper Neutralization of Input During Web Page Generation ('Cr CVE-2025-22262 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...) NOT-FOR-US: WordPress plugin CVE-2025-22150 (Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to v ...) - TODO: check + - node-undici <unfixed> + NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-c76h-2ccp-4975 + NOTE: Fixed by: https://github.com/nodejs/undici/commit/711e20772764c29f6622ddc937c63b6eefdf07d0 (v5.28.5) + NOTE: Fixed by: https://github.com/nodejs/undici/commit/c3acc6050b781b827d80c86cbbab34f14458d385 (v6.21.1) + NOTE: Fixed by: https://github.com/nodejs/undici/commit/c2d78cd19fe4f4c621424491e26ce299e65e934a (v7.2.3) CVE-2025-0623 REJECTED CVE-2025-0615 (Input validation vulnerability in Qualifio's Wheel of Fortune. This vu ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/99b9bd085c30d3243daf8812f6835e7a7360f6f8 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/99b9bd085c30d3243daf8812f6835e7a7360f6f8 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits