Bug 27767

Summary: groovy new security issue CVE-2020-17521
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Java Stack Maintainers <java>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: major    
Priority: Normal    
Version: 7   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: groovy-2.4.8-1.mga7.src.rpm CVE:
Status comment: Fixed upstream in 2.4.21

Description David Walser 2020-12-06 19:08:25 CET
Apache has issued an advisory today (December 6):
https://www.openwall.com/lists/oss-security/2020/12/06/1

The issue is fixed upstream in 2.4.21.
Comment 1 David Walser 2020-12-24 16:33:04 CET
SUSE has issued an advisory for this on December 22:
https://lists.suse.com/pipermail/sle-security-updates/2020-December/008109.html
David Walser 2020-12-28 19:15:08 CET

Status comment: (none) => Fixed upstream in 2.4.21

Comment 2 David Walser 2021-01-01 18:39:04 CET
openSUSE has issued an advisory for this on December 31:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYXXLFFWNBEOWRTRF6VZBDCDBSGYTI4L/
Comment 3 David Walser 2021-07-01 18:26:33 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED