summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2021-11-25 22:14:12 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2021-11-25 22:14:12 +0100
commit8e08b827fa72c3f9a240010aefa99bac511bcc16 (patch)
treea9eb4e07b0c3fff0fe1d234333c5c87cbe99fc2e
parent717b0680fd5d9b471ca8c30690048e3ec1668548 (diff)
Reference blog post for CVE-2021-41270
-rw-r--r--data/CVE/2021.list1
1 files changed, 1 insertions, 0 deletions
diff --git a/data/CVE/2021.list b/data/CVE/2021.list
index 4d25ea4cc4..0f858d0515 100644
--- a/data/CVE/2021.list
+++ b/data/CVE/2021.list
@@ -6853,6 +6853,7 @@ CVE-2021-41270 (Symfony/Serializer handles serializing and deserializing data st
- symfony 4.4.19+dfsg-3
NOTE: https://github.com/symfony/symfony/security/advisories/GHSA-2xhg-w2g5-w95x
NOTE: https://github.com/symfony/symfony/commit/3da6f2d45e7536ccb2a26f52fbaf340917e208a8 (v4.4.35)
+ NOTE: https://symfony.com/blog/cve-2021-41270-prevent-csv-injection-via-formulas
CVE-2021-41269 (cron-utils is a Java library to define, parse, validate, migrate crons ...)
NOT-FOR-US: cron-utils Java library
CVE-2021-41268 (Symfony/SecurityBundle is the security system for Symfony, a PHP frame ...)

© 2014-2024 Faster IT GmbH | imprint | privacy policy