From f5fe018e3cd02aeb21cac08613d53e55e10835d9 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 22 Feb 2022 07:29:28 +0100 Subject: Track two issues in geckodriver, itp'ed --- data/CVE/list.2020 | 2 +- data/CVE/list.2021 | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/data/CVE/list.2020 b/data/CVE/list.2020 index b906363eec..654068a6d0 100644 --- a/data/CVE/list.2020 +++ b/data/CVE/list.2020 @@ -35292,7 +35292,7 @@ CVE-2020-15661 (A rogue webpage could override the injected WKUserScript used by - firefox (Specific to Firefox for iOS) NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2020-34/#CVE-2020-15661 CVE-2020-15660 (Missing checks on Content-Type headers in geckodriver before 0.27.0 co ...) - NOT-FOR-US: geckodriver + - geckodriver (bug #989456) CVE-2020-15659 (Mozilla developers and community members reported memory safety bugs p ...) {DSA-4740-1 DSA-4736-1 DLA-2310-1 DLA-2297-1} - firefox 79.0-1 diff --git a/data/CVE/list.2021 b/data/CVE/list.2021 index 98f2a707c6..13bc719b4d 100644 --- a/data/CVE/list.2021 +++ b/data/CVE/list.2021 @@ -3788,6 +3788,7 @@ CVE-2021-4139 (pimcore is vulnerable to Improper Neutralization of Input During NOT-FOR-US: Pimcore CVE-2021-4138 RESERVED + - geckodriver (bug #989456) CVE-2021-45233 RESERVED CVE-2021-45232 (In Apache APISIX Dashboard before 2.10.1, the Manager API uses two fra ...) -- cgit v1.2.3