HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.
Category Archives: Advisories
varnish-modules-0.19.0-5.fc36
FEDORA-2022-99702d9bdd
Packages in this update:
varnish-modules-0.19.0-5.fc36
Update description:
Rebuilt for varnish-7.0.3
CVE-2020-27834
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2020-27836
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability..
java-latest-openjdk-18.0.2.0.9-1.rolling.el7
FEDORA-EPEL-2022-21ae60f43a
Packages in this update:
java-latest-openjdk-18.0.2.0.9-1.rolling.el7
Update description:
CPU update for JDK latest
OpenImageIO-2.2.21.0-2.fc35 ctk-0.1-0.24.20190721.fc35 dcmtk-3.6.7-1.fc35
FEDORA-2022-d9f1bb102d
Packages in this update:
ctk-0.1-0.24.20190721.fc35
dcmtk-3.6.7-1.fc35
OpenImageIO-2.2.21.0-2.fc35
Update description:
Update to dcmtk 3.6.7 and re-build dependent packages.
Please note that dcmtk 3.6.7 includes security fixes, so this update is highly recommended.
OpenImageIO-2.3.18.0-2.fc36 ctk-0.1-0.24.20190721.fc36 dcmtk-3.6.7-1.fc36
FEDORA-2022-eaeeb0ca2b
Packages in this update:
ctk-0.1-0.24.20190721.fc36
dcmtk-3.6.7-1.fc36
OpenImageIO-2.3.18.0-2.fc36
Update description:
Update dcmtk to 3.6.7 and rebuild dependent packages.
The dcmtk update contains security fixes, so this update is highly recommended.
golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc37
FEDORA-2022-21aa9bae12
Packages in this update:
golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc37
Update description:
Automatic update for golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc37.
Changelog
* Sun Aug 21 2022 Robert-André Mauchin <zebob.m@gmail.com> 2.8.1-2
– Update to 2.8.1, commit bc6b7455cb168d3000c18714ee1c57d2cd03b953 – Close:
rhbz#2043861 rhbz#2067428 rhbz#2067396 rhbz#2045498
* Sun Aug 21 2022 Robert-André Mauchin <zebob.m@gmail.com> 2.8.1-1
– Update to 2.8.1, commit bc6b7455cb168d3000c18714ee1c57d2cd03b953 – Close:
rhbz#2043861 rhbz#2067428 rhbz#2067396 rhbz#2045498
* Wed Aug 10 2022 Maxwell G <gotmax@e.email> – 2.7.1-12
– Rebuild to fix FTBFS
* Thu Jul 21 2022 Fedora Release Engineering <releng@fedoraproject.org> – 2.7.1-11
– Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Tue Jul 19 2022 Maxwell G <gotmax@e.email> – 2.7.1-10
– Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in
golang
* Sat Jun 18 2022 Robert-André Mauchin <zebob.m@gmail.com> – 2.7.1-9
– Rebuilt for CVE-2022-1996, CVE-2022-24675, CVE-2022-28327, CVE-2022-27191,
CVE-2022-29526, CVE-2022-30629
* Thu Jan 20 2022 Fedora Release Engineering <releng@fedoraproject.org> – 2.7.1-8
– Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc38
FEDORA-2022-59cb9da3d4
Packages in this update:
golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc38
Update description:
Automatic update for golang-github-docker-distribution-2.8.1-2.20220821gitbc6b745.fc38.
Changelog
* Sun Aug 21 2022 Robert-André Mauchin <zebob.m@gmail.com> 2.8.1-2
– Update to 2.8.1, commit bc6b7455cb168d3000c18714ee1c57d2cd03b953 – Close:
rhbz#2043861 rhbz#2067428 rhbz#2067396 rhbz#2045498
* Sun Aug 21 2022 Robert-André Mauchin <zebob.m@gmail.com> 2.8.1-1
– Update to 2.8.1, commit bc6b7455cb168d3000c18714ee1c57d2cd03b953 – Close:
rhbz#2043861 rhbz#2067428 rhbz#2067396 rhbz#2045498
* Wed Aug 10 2022 Maxwell G <gotmax@e.email> – 2.7.1-12
– Rebuild to fix FTBFS
* Thu Jul 21 2022 Fedora Release Engineering <releng@fedoraproject.org> – 2.7.1-11
– Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Tue Jul 19 2022 Maxwell G <gotmax@e.email> – 2.7.1-10
– Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in
golang
* Sat Jun 18 2022 Robert-André Mauchin <zebob.m@gmail.com> – 2.7.1-9
– Rebuilt for CVE-2022-1996, CVE-2022-24675, CVE-2022-28327, CVE-2022-27191,
CVE-2022-29526, CVE-2022-30629
* Thu Jan 20 2022 Fedora Release Engineering <releng@fedoraproject.org> – 2.7.1-8
– Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild