| Summary: | hibernate-validator new security issues CVE-2017-7536 and CVE-2020-10693 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Java Stack Maintainers <java> |
| Status: | RESOLVED OLD | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | mageia |
| Version: | 7 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | hibernate-validator-5.2.4-1.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2018-10-17 23:41:09 CEST
David Walser
2018-10-17 23:41:16 CEST
Whiteboard:
(none) =>
MGA6TOO
David Walser
2019-06-23 19:31:23 CEST
Whiteboard:
MGA6TOO =>
MGA7TOO, MGA6TOO
Nicolas Lécureuil
2020-05-22 14:08:48 CEST
Whiteboard:
MGA7TOO, MGA6TOO =>
MGA7TOO This package has been (mercifully) dropped in Cauldron. RedHat has issued an advisory on October 27: https://access.redhat.com/errata/RHSA-2020:4366 It fixes a new issue in hibernate-validator that was fixed upstream in 6.0.20. The original CVE in this bug was fixed upstream in 5.3.5. Summary:
hibernate-validator new security issue CVE-2017-7536 =>
hibernate-validator new security issues CVE-2017-7536 and CVE-2020-10693
David Walser
2020-10-29 02:07:37 CET
Whiteboard:
MGA7TOO =>
(none) https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/ Status:
NEW =>
RESOLVED |