Category Archives: Advisories

CVE-2019-25075

Read Time:9 Second

HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.

Read More

CVE-2020-27834

Read Time:9 Second

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Read More

CVE-2020-27836

Read Time:17 Second

A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability..

Read More

golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc37

Read Time:1 Minute, 11 Second

FEDORA-2022-21aa9bae12

Packages in this update:

golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc37

Update description:

Automatic update for golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc37.

Changelog

* Sun Aug 21 2022 Robert-André Mauchin <zebob.m@gmail.com> 2.8.1-2
– Update to 2.8.1, commit bc6b7455cb168d3000c18714ee1c57d2cd03b953 – Close:
rhbz#2043861 rhbz#2067428 rhbz#2067396 rhbz#2045498
* Sun Aug 21 2022 Robert-André Mauchin <zebob.m@gmail.com> 2.8.1-1
– Update to 2.8.1, commit bc6b7455cb168d3000c18714ee1c57d2cd03b953 – Close:
rhbz#2043861 rhbz#2067428 rhbz#2067396 rhbz#2045498
* Wed Aug 10 2022 Maxwell G <gotmax@e.email> – 2.7.1-12
– Rebuild to fix FTBFS
* Thu Jul 21 2022 Fedora Release Engineering <releng@fedoraproject.org> – 2.7.1-11
– Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Tue Jul 19 2022 Maxwell G <gotmax@e.email> – 2.7.1-10
– Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in
golang
* Sat Jun 18 2022 Robert-André Mauchin <zebob.m@gmail.com> – 2.7.1-9
– Rebuilt for CVE-2022-1996, CVE-2022-24675, CVE-2022-28327, CVE-2022-27191,
CVE-2022-29526, CVE-2022-30629
* Thu Jan 20 2022 Fedora Release Engineering <releng@fedoraproject.org> – 2.7.1-8
– Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild

Read More

golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc38

Read Time:1 Minute, 11 Second

FEDORA-2022-59cb9da3d4

Packages in this update:

golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc38

Update description:

Automatic update for golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc38.

Changelog

* Sun Aug 21 2022 Robert-André Mauchin <zebob.m@gmail.com> 2.8.1-2
– Update to 2.8.1, commit bc6b7455cb168d3000c18714ee1c57d2cd03b953 – Close:
rhbz#2043861 rhbz#2067428 rhbz#2067396 rhbz#2045498
* Sun Aug 21 2022 Robert-André Mauchin <zebob.m@gmail.com> 2.8.1-1
– Update to 2.8.1, commit bc6b7455cb168d3000c18714ee1c57d2cd03b953 – Close:
rhbz#2043861 rhbz#2067428 rhbz#2067396 rhbz#2045498
* Wed Aug 10 2022 Maxwell G <gotmax@e.email> – 2.7.1-12
– Rebuild to fix FTBFS
* Thu Jul 21 2022 Fedora Release Engineering <releng@fedoraproject.org> – 2.7.1-11
– Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Tue Jul 19 2022 Maxwell G <gotmax@e.email> – 2.7.1-10
– Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in
golang
* Sat Jun 18 2022 Robert-André Mauchin <zebob.m@gmail.com> – 2.7.1-9
– Rebuilt for CVE-2022-1996, CVE-2022-24675, CVE-2022-28327, CVE-2022-27191,
CVE-2022-29526, CVE-2022-30629
* Thu Jan 20 2022 Fedora Release Engineering <releng@fedoraproject.org> – 2.7.1-8
– Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild

Read More