From b8e325e5edb09a52d5e195df3f1b6af7082245c7 Mon Sep 17 00:00:00 2001 From: Markus Koschany Date: Mon, 6 Dec 2021 17:34:28 +0100 Subject: Mark CVE-2020-18670,CVE-2020-18671 in roundcube as ignore instead of postponed Those issues are borderline unimportant and can be safely ignored. --- data/CVE/list | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/data/CVE/list b/data/CVE/list index 0c7f73d2f7..5fa5217d15 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -96737,13 +96737,13 @@ CVE-2020-18672 CVE-2020-18671 (Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 ...) - roundcube 1.4.5+dfsg.1-1 [buster] - roundcube 1.3.13+dfsg.1-1~deb10u1 - [stretch] - roundcube (Minor issue, XSS in installer which is not exposed in Debian) + [stretch] - roundcube (Minor issue, XSS in installer which is not exposed in Debian) NOTE: https://github.com/roundcube/roundcubemail/issues/7406 NOTE: https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12 CVE-2020-18670 (Cross Site Scripting (XSS) vulneraibility in Roundcube mail .4.4 via d ...) - roundcube 1.4.5+dfsg.1-1 [buster] - roundcube 1.3.13+dfsg.1-1~deb10u1 - [stretch] - roundcube (Minor issue, XSS in installer which is not exposed in Debian) + [stretch] - roundcube (Minor issue, XSS in installer which is not exposed in Debian) NOTE: https://github.com/roundcube/roundcubemail/issues/7406 NOTE: https://roundcube.net/news/2020/06/02/security-updates-1.4.5-and-1.3.12 CVE-2020-18669 -- cgit v1.2.3