Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 7: 2021-0206 Important Advisory for Pagure XSS Threat

mageia
Calendar Grey May 7, 2021
Dist Mageia Esm H88
Recent updates to Pagure packages tackle a critical XSS security flaw in Mageia, providing solutions for vulnerabilities discovered on 07 May 2021.
Pagure before 5.6 allows XSS via the templates/blame.html blame view

Summary

Pagure before 5.6 allows XSS via the templates/blame.html blame view.

References

- https://bugs.mageia.org/show_bug.cgi?id=27487

- https://bugzilla.suse.com/show_bug.cgi?id=1176987

- https://pagure.io/pagure/c/31a0d2950ed409550074ca52ba492f9b87ec3318

- https://www.cve.org/CVERecord?id=CVE-2019-11556

Resolution

SRPMS

- 7/core/pagure-5.5-1.1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 07 May 2021
URL: https://advisories.mageia.org/MGASA-2021-0206.html
Type: security
CVE: CVE-2019-11556

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here