Date: Sun, 28 Apr 2024 14:07:20 GMT From: Kai Knoblich <kai@FreeBSD.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org Subject: git: c91e00f9e630 - main - security/vuxml: Amend previous commit 3b46eb72e1df Message-ID: <202404281407.43SE7KZZ087332@gitrepo.freebsd.org>
next in thread | raw e-mail | index | archive | help
The branch main has been updated by kai: URL: https://cgit.FreeBSD.org/ports/commit/?id=c91e00f9e630db8dc4ba6e7417ca9ca27793867e commit c91e00f9e630db8dc4ba6e7417ca9ca27793867e Author: Kai Knoblich <kai@FreeBSD.org> AuthorDate: 2024-04-28 13:54:32 +0000 Commit: Kai Knoblich <kai@FreeBSD.org> CommitDate: 2024-04-28 14:06:37 +0000 security/vuxml: Amend previous commit 3b46eb72e1df Add a missing paragraph, which was not found by "make validate" before committing. Fixes: 3b46eb72e1df security/vuxml: Document www/py-social-auth-app-django vulnerability --- security/vuxml/vuln/2024.xml | 1 + 1 file changed, 1 insertion(+) diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index 13bc01b83dfc..b09536e6f506 100644 --- a/security/vuxml/vuln/2024.xml +++ b/security/vuxml/vuln/2024.xml @@ -11,6 +11,7 @@ </affects> <description> <body xmlns="http://www.w3.org/1999/xhtml"> + <p>GitHub Advisory Database:</p> <blockquote cite="https://nvd.nist.gov/vuln/detail/CVE-2024-32879"> <p>Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match. This issue has been addressed by a fix released in version 5.4.1. An immediate workaround would be to change collation of the affected field.</p> </blockquote>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202404281407.43SE7KZZ087332>