Summary: | <dev-util/reviewboard-1.7.28: Multiple Vulnerabilities (CVE-2013-{4409,4410,4411,4795}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Yury German <blueknight> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | CC: | idella4 |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://www.reviewboard.org/docs/releasenotes/reviewboard/ | ||
Whiteboard: | ~3 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Yury German
![]() ![]() CVE-2013-4795 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4795): Cross-site scripting (XSS) vulnerability in the Submitters list in Review Board 1.6.x before 1.6.18 and 1.7.x before 1.7.12 allows remote attackers to inject arbitrary web script or HTML via a user full name. Please upgrade in bug 522472 to Version 1.7.27 or above, setting dependency. Maintainer(s), Thank you for your work. No GLSA needed as there are no stable versions. |