Date: Fri, 27 Mar 2020 13:48:12 +0000 (UTC) From: Wen Heping <wen@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r529248 - head/security/vuxml Message-ID: <202003271348.02RDmCOr040577@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: wen Date: Fri Mar 27 13:48:12 2020 New Revision: 529248 URL: https://svnweb.freebsd.org/changeset/ports/529248 Log: - Document mediawiki's multiple vulnerabilities Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Fri Mar 27 13:39:56 2020 (r529247) +++ head/security/vuxml/vuln.xml Fri Mar 27 13:48:12 2020 (r529248) @@ -58,6 +58,41 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="090763f6-7030-11ea-93dd-080027846a02"> + <topic>mediawiki -- multiple vulnerabilities</topic> + <affects> + <package> + <name>mediawiki131</name> + <range><lt>1.31.7</lt></range> + </package> + <package> + <name>mediawiki133</name> + <range><lt>1.33.3</lt></range> + </package> + <package> + <name>mediawiki134</name> + <range><lt>1.34.1</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Mediawiki reports:</p> + <blockquote cite="https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-March/000247.html"> + <p>Security fixes: + T246602:jquery.makeCollapsible allows applying event handler to any CSS + selector.</p> + </blockquote> + </body> + </description> + <references> + <url>https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-March/000247.html</url> + </references> + <dates> + <discovery>2020-03-02</discovery> + <entry>2020-03-27</entry> + </dates> + </vuln> + <vuln vid="08fba28b-6f9f-11ea-bd0b-001b217b3468"> <topic>Gitlab -- Multiple Vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202003271348.02RDmCOr040577>