Debian alert DLA-2545-1 (open-build-service)
From: | Utkarsh Gupta <utkarsh@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 2545-1] open-build-service security update | |
Date: | Wed, 03 Feb 2021 18:00:50 +0530 | |
Message-ID: | <CAPP0f95M2RaWnf-CMpUWC9sO7c8u87-6qoEQbUVj+CAz--B+zQ@mail.gmail.com> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2545-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta February 03, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : open-build-service Version : 2.7.1-10+deb9u1 CVE ID : CVE-2020-8020 CVE-2020-8021 CVE-2020-8020 An improper neutralization of input during web page generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. CVE-2020-8021 An improper access control vulnerability in open-build-service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled. For Debian 9 stretch, these problems have been fixed in version 2.7.1-10+deb9u1. We recommend that you upgrade your open-build-service packages. For the detailed security status of open-build-service please refer to its security tracker page at: https://security-tracker.debian.org/tracker/open-build-service Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmAal0cACgkQgj6WdgbD S5Ze2A/7Bp4G1BDMNkLMkvFWGqGDP4mt4lUzCP3RyFxPJ3NfSxhVKVayEuZ1KYAD iFUn9BIrubMeMPzaVPGrQnL6Lxli3HUstx0XglSAGwFxX0u1Pzpgf16zpmxzyRga yGgz8lwzLRs9StuuEluuFZG7N+S3Slx9nz8srNcfJVCc7FMrou/DzG4W3shf9aLR 4dpW8vdqZMXhN+SprvBS0BdtdKPqHSBkK8oMGMBed1ya+UjQdOtvV/ZEPQlPgMGc QQxQwHPqDOEOE5EWxXif2nwoCfaRo43caM9qdvI9dkOaylO5eZ1Az8Ih4UjoFacJ QyUYpRzG2yvDSS6G+SCtgMWp/OTHzt1OIRhmaCrY+Wzo7KGORNzOB2zOQogyMu/y Wr3sAMd1eQMkJJ5blMcS0s2gICBGECedaW2iS0wj4gZ6lczDpDiw+tmIh6UqKwKT lsxTDRen028YSolhphdD5ZGde1JtGNAFPtcxkIwH7xiu9Bp/6BbUQAxzdRR1fMHy /eyLX0F31gli7hS1XEAxXy07nWwrx2i2X/y8NgDzBREXTLvoxoVCtpW40GjF15Td 9mfKOZ7qdjxMngmybgRi29OluAq796CoGHqtUHIIDJRFTn5Ob7AVNKMkGQzAdyOU xuOCigBKIfZbtoN5f7o6nmenjB3LEgEukZQAzWHEgZXW9ajWp4w= =MIG9 -----END PGP SIGNATURE-----