An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
CVE: (none) => CVE-2020-25789
Summary: Security vulnerabilities for tt-rss CVE-2020-25789 => tt-rss new security issue CVE-2020-25789Source RPM: tt-rss-1.12-8.mga7.src => tt-rss-1.12-9.mga8.src.rpmWhiteboard: (none) => MGA7TOOVersion: 7 => Cauldron
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25789
Hi, thanks for reporting this. I added the committers in CC. (Please set the status to 'assigned' if you are working on it)
Assignee: bugsquad => mageiaCC: (none) => jani.valimaa, thierry.vignaud
The code that was patched upstream is very different than the code we have. We may not be affected.
Status comment: (none) => include/functions.php needs to not serve SVG images
except if someone show us we are affected, i looked and it seems we are not ( 99% sure :-) )
Resolution: (none) => INVALIDStatus: NEW => RESOLVEDCC: (none) => mageia