From 28f194e6763f03ffb55d94bcc8b334152734d04f Mon Sep 17 00:00:00 2001 From: Thorsten Alteholz Date: Sat, 27 Nov 2021 00:30:49 +0100 Subject: mark CVE-2020-27511 as no-dsa for Stretch --- data/CVE/2020.list | 1 + 1 file changed, 1 insertion(+) diff --git a/data/CVE/2020.list b/data/CVE/2020.list index 498a1b39db..628da07fe6 100644 --- a/data/CVE/2020.list +++ b/data/CVE/2020.list @@ -8797,6 +8797,7 @@ CVE-2020-27512 CVE-2020-27511 (An issue was discovered in the stripTags and unescapeHTML components i ...) - prototypejs (bug #991898) [bullseye] - prototypejs (Minor issue) + [stretch] - prototypejs (Minor issue) NOTE: https://github.com/prototypejs/prototype/blame/dee2f7d8611248abce81287e1be4156011953c90/src/prototype/lang/string.js#L283 NOTE: https://github.com/yetingli/PoCs/blob/main/CVE-2020-27511/Prototype.md NOTE: CVE mentions newer version but vulnerable code exists in older versions too -- cgit v1.2.3