CVE-2020-11988: Apache XmlGraphics Commons 2.4 is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Please bump.
Forgot to mention this bug https://gitweb.gentoo.org/repo/gentoo.git/commit/dev-java/xmlgraphics-commons?id=2fa64ba45e00e389bbf7005578ad7ff3a8f50151
the tests are passing and the consumers compile fine against this version so imo can be stabilized.
Thanks!
x86 done
amd64 done
ppc64 stable. Maintainer(s), please cleanup. Security, please vote.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=dfb3c9a6963b80d6c218462b859ac80ece3c3b1e commit dfb3c9a6963b80d6c218462b859ac80ece3c3b1e Author: Miroslav Šulc <fordfrog@gentoo.org> AuthorDate: 2021-06-18 06:37:11 +0000 Commit: Miroslav Šulc <fordfrog@gentoo.org> CommitDate: 2021-06-18 06:37:11 +0000 dev-java/xmlgraphics-commons: removed vulnerable 2.0.1 Bug: https://bugs.gentoo.org/772929 Package-Manager: Portage-3.0.20, Repoman-3.0.3 Signed-off-by: Miroslav Šulc <fordfrog@gentoo.org> dev-java/xmlgraphics-commons/Manifest | 1 - .../xmlgraphics-commons-2.0.1.ebuild | 63 ---------------------- 2 files changed, 64 deletions(-)
the tree is clean now, you can proceed.
Thank you!
Keywords are not fully specified and arches are not CC-ed for the following packages: - =dev-java/xmlgraphics-commons-2.6
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=a3dd94d7603f38c077b0de0e219e64b92153b6c9 commit a3dd94d7603f38c077b0de0e219e64b92153b6c9 Author: Volkmar W. Pogatzki <gentoo@pogatzki.net> AuthorDate: 2022-02-26 07:07:33 +0000 Commit: Miroslav Šulc <fordfrog@gentoo.org> CommitDate: 2022-02-26 08:43:57 +0000 dev-java/xmlgraphics-commons: Drop 2.6 Bug: https://bugs.gentoo.org/772929 Package-Manager: Portage-3.0.30, Repoman-3.0.3 Signed-off-by: Volkmar W. Pogatzki <gentoo@pogatzki.net> Closes: https://github.com/gentoo/gentoo/pull/24353 Signed-off-by: Miroslav Šulc <fordfrog@gentoo.org> dev-java/xmlgraphics-commons/Manifest | 1 - .../xmlgraphics-commons-2.6.ebuild | 75 ---------------------- 2 files changed, 76 deletions(-)
Unable to check for sanity: > no match for package: dev-java/xmlgraphics-commons-2.6