| Summary: | python-werkzeug new security issues CVE-2023-23934 and CVE-2023-25577 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Python Stack Maintainers <python> |
| Status: | RESOLVED OLD | QA Contact: | Sec team <security> |
| Severity: | critical | ||
| Priority: | Normal | CC: | mageia, nicolas.salguero, yvesbrungard |
| Version: | 8 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | python-werkzeug-1.0.1-1.mga8.src.rpm | CVE: | |
| Status comment: | Fixed upstream in 2.2.3 | ||
|
Description
David Walser
2023-03-02 02:25:29 CET
David Walser
2023-03-02 02:25:42 CET
Status comment:
(none) =>
Fixed upstream in 2.2.3 This is nominally with NicolasL, who commited v2.2.2; CC'ing him, assigning to Pÿthon maintainers. Assignee:
bugsquad =>
python Fedora has issued an advisory for this on March 11: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/M2GTOE47WJ7BTBX2ENLG3VMBHVJQPH2D/ It looks like python-flask should be updated with this: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/OPHK7NCUAEEG647ETCSFYCZP47H4D7XV/ Fedora advisory that actually has CVE references: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/VTNTWI7NG5ZWHOUWADRZKPL3DMYZNC3Z/ Ubuntu has issued an advisory for this on March 13: https://ubuntu.com/security/notices/USN-5948-1 Summary:
python-werzkeug new security issues CVE-2023-23934 and CVE-2023-25577 =>
python-werkzeug new security issues CVE-2023-23934 and CVE-2023-25577 This is done since 2023-03-14 for cauldron by David G Version:
Cauldron =>
8 More specifically, python-werkzeug-2.2.3-1.mga9 was uploaded. Source RPM:
python-werkzeug-2.2.2-1.mga9.src.rpm =>
python-werkzeug-1.0.1-1.mga8.src.rpm Mageia 8 EOL Status:
NEW =>
RESOLVED |