| Summary: | springframework new security issues CVE-2018-1257, CVE-2018-1270, CVE-2018-11039, CVE-2018-11040, CVE-2018-15756, CVE-2020-5421 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Java Stack Maintainers <java> |
| Status: | RESOLVED OLD | QA Contact: | Sec team <security> |
| Severity: | critical | ||
| Priority: | Normal | CC: | mageia, zombie_ryushu |
| Version: | 7 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | springframework-3.2.18-2.mga7.src.rpm | CVE: | CVE-2020-5421 |
| Status comment: | |||
|
Description
David Walser
2018-12-08 19:00:14 CET
David Walser
2018-12-08 19:00:21 CET
Whiteboard:
(none) =>
MGA6TOO
David Walser
2019-06-23 19:31:59 CEST
Whiteboard:
MGA6TOO =>
MGA7TOO, MGA6TOO
Nicolas Lécureuil
2020-05-22 14:08:03 CEST
CC:
(none) =>
mageia
Zombie Ryushu
2020-12-23 23:13:37 CET
CVE:
(none) =>
CVE-2020-5421 Another issue fixed in newer branches, but would need to be backported: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5421 https://nvd.nist.gov/vuln/detail/CVE-2020-5421 Package was (mercifully) dropped from Cauldron. Whiteboard:
MGA7TOO =>
(none) Debian-LTS has issued an advisory on April 23: https://www.debian.org/lts/security/2021/dla-2635 The issues are fixed upstream in 4.3.20. Severity:
normal =>
critical https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/ Resolution:
(none) =>
OLD |