vuln-list-alt/oval/c10f2/ALT-PU-2023-6314/definitions.json
2024-04-16 14:26:14 +00:00

109 lines
4.1 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20236314",
"Version": "oval:org.altlinux.errata:def:20236314",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2023-6314: package `gem-redcarpet` update to version 3.5.1.1-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f2"
]
}
],
"References": [
{
"RefID": "ALT-PU-2023-6314",
"RefURL": "https://errata.altlinux.org/ALT-PU-2023-6314",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-03625",
"RefURL": "https://bdu.fstec.ru/vul/2021-03625",
"Source": "BDU"
},
{
"RefID": "CVE-2020-26298",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-26298",
"Source": "CVE"
}
],
"Description": "This update upgrades gem-redcarpet to version 3.5.1.1-alt1. \nSecurity Fix(es):\n\n * BDU:2021-03625: Уязвимость библиотеки Ruby для парсинга Markdown в HTML Redcarpet, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность защищаемой информации\n\n * CVE-2020-26298: Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-04-14"
},
"Updated": {
"Date": "2024-04-14"
},
"BDUs": [
{
"ID": "BDU:2021-03625",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://bdu.fstec.ru/vul/2021-03625",
"Impact": "Low",
"Public": "20210113"
}
],
"CVEs": [
{
"ID": "CVE-2020-26298",
"CVSS": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-26298",
"Impact": "Low",
"Public": "20210111"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:5001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20236314001",
"Comment": "gem-redcarpet is earlier than 0:3.5.1.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20236314002",
"Comment": "gem-redcarpet-devel is earlier than 0:3.5.1.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20236314003",
"Comment": "gem-redcarpet-doc is earlier than 0:3.5.1.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20236314004",
"Comment": "redcarpet is earlier than 0:3.5.1.1-alt1"
}
]
}
]
}
}
]
}