{"cves":[{"id":"CVE-2018-15645","published":"2020-12-22T17:15:00","updated_at":"2025-08-25T22:48:17.726131+00:00","description":"\nImproper access control in message routing in Odoo Community 12.0 and\nearlier and Odoo Enterprise 12.0 and earlier allows remote authenticated\nusers to create arbitrary records via crafted payloads, which may allow\nprivilege escalation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/odoo/odoo/issues/63705","https://www.cve.org/CVERecord?id=CVE-2018-15645"],"bugs":[""],"patches":{"odoo":[]},"tags":{},"packages":[{"name":"odoo","source":"https://ubuntu.com/security/cve?package=odoo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=odoo","debian":"https://tracker.debian.org/pkg/odoo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-15641","published":"2020-12-22T17:15:00","updated_at":"2025-08-25T22:48:17.726131+00:00","description":"\nCross-site scripting (XSS) issue in web module in Odoo Community 11.0\nthrough 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote\nauthenticated internal users to inject arbitrary web script in the browser\nof a victim via crafted calendar event attributes.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/odoo/odoo/issues/63704","https://github.com/odoo/odoo/commit/2876991646fdc8373f64f63764923001fe7746b4","https://www.cve.org/CVERecord?id=CVE-2018-15641"],"bugs":[""],"patches":{"odoo":[]},"tags":{},"packages":[{"name":"odoo","source":"https://ubuntu.com/security/cve?package=odoo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=odoo","debian":"https://tracker.debian.org/pkg/odoo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-15638","published":"2020-12-22T17:15:00","updated_at":"2025-08-25T22:48:17.726131+00:00","description":"\nCross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and\nearlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to\ninject arbitrary web script in the browser of a victim via crafted channel\nnames.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/odoo/odoo/issues/63703","https://www.cve.org/CVERecord?id=CVE-2018-15638"],"bugs":[""],"patches":{"odoo":[]},"tags":{},"packages":[{"name":"odoo","source":"https://ubuntu.com/security/cve?package=odoo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=odoo","debian":"https://tracker.debian.org/pkg/odoo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-15634","published":"2020-12-22T17:15:00","updated_at":"2025-08-25T22:48:17.726131+00:00","description":"\nCross-site scripting (XSS) issue in attachment management in Odoo Community\n14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote\nattackers to inject arbitrary web script in the browser of a victim via a\ncrafted link.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/odoo/odoo/issues/63702","https://github.com/odoo/odoo/commit/88e5d2df8d8d56881003320cbebaf95ed9ca7101","https://www.cve.org/CVERecord?id=CVE-2018-15634"],"bugs":[""],"patches":{"odoo":[]},"tags":{},"packages":[{"name":"odoo","source":"https://ubuntu.com/security/cve?package=odoo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=odoo","debian":"https://tracker.debian.org/pkg/odoo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-15633","published":"2020-12-22T17:15:00","updated_at":"2025-08-25T22:48:13.288835+00:00","description":"\nCross-site scripting (XSS) issue in \"document\" module in Odoo Community\n11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote\nattackers to inject arbitrary web script in the browser of a victim via\ncrafted attachment filenames.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/odoo/odoo/issues/63701","https://www.cve.org/CVERecord?id=CVE-2018-15633"],"bugs":[""],"patches":{"odoo":[]},"tags":{},"packages":[{"name":"odoo","source":"https://ubuntu.com/security/cve?package=odoo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=odoo","debian":"https://tracker.debian.org/pkg/odoo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-15632","published":"2020-12-22T17:15:00","updated_at":"2025-08-25T22:48:13.288835+00:00","description":"\nImproper input validation in database creation logic in Odoo Community 11.0\nand earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers\nto initialize an empty database on which they can connect with default\ncredentials.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/odoo/odoo/issues/63700","https://www.cve.org/CVERecord?id=CVE-2018-15632"],"bugs":[""],"patches":{"odoo":[]},"tags":{},"packages":[{"name":"odoo","source":"https://ubuntu.com/security/cve?package=odoo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=odoo","debian":"https://tracker.debian.org/pkg/odoo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-26284","published":"2020-12-21T23:15:00","updated_at":"2025-08-25T23:24:31.392945+00:00","description":"\nHugo is a fast and Flexible Static Site Generator built in Go. Hugo depends\non Go's `os/exec` for certain features, e.g. for rendering of Pandoc\ndocuments if these binaries are found in the system `%PATH%` on Windows. In\nHugo before version 0.79.1, if a malicious file with the same name (`exe`\nor `bat`) is found in the current working directory at the time of running\n`hugo`, the malicious command will be invoked instead of the system one.\nWindows users who run `hugo` inside untrusted Hugo sites are affected.\nUsers should upgrade to Hugo v0.79.1. Other than avoiding untrusted Hugo\nsites, there is no workaround.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/gohugoio/hugo/security/advisories/GHSA-8j34-9876-pvfq","https://github.com/golang/go/issues/38736","https://www.cve.org/CVERecord?id=CVE-2020-26284"],"bugs":[""],"patches":{"hugo":[]},"tags":{},"packages":[{"name":"hugo","source":"https://ubuntu.com/security/cve?package=hugo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hugo","debian":"https://tracker.debian.org/pkg/hugo","statuses":[{"release_codename":"impish","status":"not-affected","description":"Only affects Windows","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"Only affects Windows","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"Only affects Windows","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.79.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"Only affects Windows","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"Only affects Windows","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"Only affects Windows","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.102.3-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-35605","published":"2020-12-21T20:15:00","updated_at":"2025-08-25T23:26:13.001785+00:00","description":"\nThe Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows\nremote attackers to execute arbitrary code because a filename containing\nspecial characters can be included in an error message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-5659-1","https://www.cve.org/CVERecord?id=CVE-2020-35605"],"bugs":["https://github.com/kovidgoyal/kitty/issues/3128"],"patches":{"kitty":["upstream: https://github.com/kovidgoyal/kitty/commit/82c137878c2b99100a3cdc1c0f0efea069313901"]},"tags":{},"packages":[{"name":"kitty","source":"https://ubuntu.com/security/cve?package=kitty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kitty","debian":"https://tracker.debian.org/pkg/kitty","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.21.2-1build1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.21.2-1build1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.15.0-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.19.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-5659-1"],"notices":[{"id":"USN-5659-1","title":"kitty vulnerabilities","summary":"kitty could be made to run programs if it opened a specially\ncrafted image or desktop notification.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-10-05T23:59:34.051792","description":"Stephane Chauveau discovered that kitty incorrectly handled image\nfilenames with special characters in error messages. A remote\nattacker could possibly use this to execute arbitrary commands.\nThis issue only affected Ubuntu 20.04 LTS. (CVE-2020-35605)\n\nCarter Sande discovered that kitty incorrectly handled escape\nsequences in desktop notifications. A remote attacker could possibly\nuse this to execute arbitrary commands. This issue only affected\nUbuntu 22.04 LTS. (CVE-2022-41322)\n","is_hidden":false,"release_packages":{"jammy":[{"name":"kitty","version":"0.21.2-1ubuntu0.22.04.1","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty-terminfo","version":"0.21.2-1ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.21.2-1ubuntu0.22.04.1","pocket":"security"},{"name":"kitty","version":"0.21.2-1ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.21.2-1ubuntu0.22.04.1","pocket":"security"},{"name":"kitty-doc","version":"0.21.2-1ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.21.2-1ubuntu0.22.04.1","pocket":"security"}],"focal":[{"name":"kitty","version":"0.15.0-1ubuntu0.2","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty-terminfo","version":"0.15.0-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.15.0-1ubuntu0.2","pocket":"security"},{"name":"kitty","version":"0.15.0-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.15.0-1ubuntu0.2","pocket":"security"},{"name":"kitty-doc","version":"0.15.0-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.15.0-1ubuntu0.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2022-41322","CVE-2020-35605"]}]},{"id":"CVE-2020-26422","published":"2020-12-21T18:15:00","updated_at":"2025-07-11T07:44:46.457969+00:00","description":"\nBuffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial\nof service via packet injection or crafted capture file","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://gitlab.com/wireshark/wireshark/-/issues/17073","https://www.wireshark.org/security/wnpa-sec-2020-20.html","https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26422.json","https://www.cve.org/CVERecord?id=CVE-2020-26422"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-26275","published":"2020-12-21T18:15:00","updated_at":"2025-08-26T12:23:08.611515+00:00","description":"\nThe Jupyter Server provides the backend (i.e. the core services, APIs, and\nREST endpoints) for Jupyter web applications like Jupyter notebook,\nJupyterLab, and Voila. In Jupyter Server before version 1.1.1, an open\nredirect vulnerability could cause the jupyter server to redirect the\nbrowser to a different malicious website. All jupyter servers running\nwithout a base_url prefix are technically affected, however, these\nmaliciously crafted links can only be reasonably made for known jupyter\nserver hosts. A link to your jupyter server may *appear* safe, but\nultimately redirect to a spoofed server on the public internet. This same\nvulnerability was patched in upstream notebook v5.7.8. This is fixed in\njupyter_server 1.1.1. If upgrade is not available, a workaround can be to\nrun your server on a url prefix: \"jupyter server\n--ServerApp.base_url=/jupyter/\".","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/jupyter-server/jupyter_server/commit/85e4abccf6ea9321d29153f73b0bd72ccb3a6bca","https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-9f66-54xg-pc2c","https://pypi.org/project/jupyter-server/","https://www.cve.org/CVERecord?id=CVE-2020-26275"],"bugs":[""],"patches":{"jupyter-server":["upstream: https://github.com/jupyter-server/jupyter_server/commit/85e4abccf6ea9321d29153f73b0bd72ccb3a6bca"]},"tags":{},"packages":[{"name":"jupyter-server","source":"https://ubuntu.com/security/cve?package=jupyter-server","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jupyter-server","debian":"https://tracker.debian.org/pkg/jupyter-server","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.18.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.18.1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.18.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.18.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.18.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.18.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.18.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-25860","published":"2020-12-21T18:15:00","updated_at":"2025-08-26T12:22:52.515835+00:00","description":"\nThe install.c module in the Pengutronix RAUC update client prior to version\n1.5 has a Time-of-Check Time-of-Use vulnerability, where signature\nverification on an update file takes place before the file is reopened for\ninstallation. An attacker who can modify the update file just before it is\nreopened can install arbitrary code on the device.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/rauc/rauc/security/advisories/GHSA-cgf3-h62j-w9vv","https://www.vdoo.com/blog/cve-2020-25860-significant-vulnerability-discovered-rauc-embedded-firmware-update-framework","https://www.cve.org/CVERecord?id=CVE-2020-25860"],"bugs":[""],"patches":{"rauc":[]},"tags":{},"packages":[{"name":"rauc","source":"https://ubuntu.com/security/cve?package=rauc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rauc","debian":"https://tracker.debian.org/pkg/rauc","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.6-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.6-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.6-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.6-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.6-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.6-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-26263","published":"2020-12-21T17:15:00","updated_at":"2025-08-26T12:23:08.611515+00:00","description":"\ntlslite-ng is an open source python library that implements SSL and TLS\ncryptographic protocols. In tlslite-ng before versions 0.7.6 and\n0.8.0-alpha39, the code that performs decryption and padding check in RSA\nPKCS#1 v1.5 decryption is data dependant. In particular, the code has\nmultiple ways in which it leaks information about the decrypted ciphertext.\nIt aborts as soon as the plaintext doesn't start with 0x00, 0x02. All TLS\nservers that enable RSA key exchange as well as applications that use the\nRSA decryption API directly are vulnerable. This is patched in versions\n0.7.6 and 0.8.0-alpha39. Note: the patches depend on Python processing the\nindividual bytes in side-channel free manner, this is known to not the case\n(see reference). As such, users that require side-channel resistance are\nrecommended to use different TLS implementations, as stated in the security\npolicy of tlslite-ng.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/tlsfuzzer/tlslite-ng/security/advisories/GHSA-wvcv-832q-fjg7","https://github.com/tlsfuzzer/tlslite-ng/commit/c28d6d387bba59d8bd5cb3ba15edc42edf54b368","https://github.com/tlsfuzzer/tlslite-ng/pull/438","https://github.com/tlsfuzzer/tlslite-ng/pull/439","https://pypi.org/project/tlslite-ng/","https://securitypitfalls.wordpress.com/2018/08/03/constant-time-compare-in-python/","https://www.cve.org/CVERecord?id=CVE-2020-26263"],"bugs":[""],"patches":{"tlslite-ng":[]},"tags":{},"packages":[{"name":"tlslite-ng","source":"https://ubuntu.com/security/cve?package=tlslite-ng","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tlslite-ng","debian":"https://tracker.debian.org/pkg/tlslite-ng","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-35573","published":"2020-12-20T05:15:00","updated_at":"2025-08-26T12:24:57.391697+00:00","description":"\nsrs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of\nservice (CPU consumption) via a long timestamp tag in an SRS address.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/roehling/postsrsd/commit/4733fb11f6bec6524bb8518c5e1a699288c26bac (1.10)","https://github.com/roehling/postsrsd/commit/4733fb11f6bec6524bb8518c5e1a699288c26bac","https://ubuntu.com/security/notices/USN-4730-1","https://www.cve.org/CVERecord?id=CVE-2020-35573"],"bugs":[""],"patches":{"postsrsd":[]},"tags":{},"packages":[{"name":"postsrsd","source":"https://ubuntu.com/security/cve?package=postsrsd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postsrsd","debian":"https://tracker.debian.org/pkg/postsrsd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.10-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.4-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.10-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.10-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.10-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.10-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.10-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.10-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.10-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4730-1"],"notices":[{"id":"USN-4730-1","title":"PostSRSd vulnerability","summary":"PostSRSd could be made to crash if it received specially crafted\ninput.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-02-10T23:07:25.360451","description":"It was discovered that PostSRSd mishandled certain input. A remote attacker\ncould use this vulnerability to cause a denial of service via a long timestamp\ntag in an SRS address.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"postsrsd","version":"1.4-1ubuntu0.1","description":"Sender Rewriting Scheme via TCP-based lookup tables for Postfix","is_source":true},{"name":"postsrsd","version":"1.4-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postsrsd","version_link":"https://launchpad.net/ubuntu/+source/postsrsd/1.4-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-35573"]}]},{"id":"CVE-2020-35480","published":"2020-12-18T08:15:00","updated_at":"2025-07-11T07:45:14.165865+00:00","description":"\nAn issue was discovered in MediaWiki before 1.35.1. Missing users (accounts\nthat don't exist) and hidden users (accounts that have been explicitly\nhidden due to being abusive, or similar) that the viewer cannot see are\nhandled differently, exposing sensitive information about the hidden status\nto unprivileged viewers. This exists on various code paths.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T120883","https://lists.wikimedia.org/pipermail/wikitech-l/2020-December/094126.html","https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.html","https://www.cve.org/CVERecord?id=CVE-2020-35480"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.35.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-35479","published":"2020-12-18T08:15:00","updated_at":"2025-07-11T07:45:14.165865+00:00","description":"\nMediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php.\nLanguage::translateBlockExpiry itself does not escape in all code paths.\nFor example, the return of Language::userTimeAndDate is is always unsafe\nfor HTML in a month value. This affects MediaWiki 1.12.0 and later.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T268938","https://lists.wikimedia.org/pipermail/wikitech-l/2020-December/094126.html","https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.html","https://www.cve.org/CVERecord?id=CVE-2020-35479"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.35.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-35478","published":"2020-12-18T08:15:00","updated_at":"2025-07-11T07:45:14.165865+00:00","description":"\nMediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php.\nMediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT\ntags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and\nlater.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T268938","https://lists.wikimedia.org/pipermail/wikitech-l/2020-December/094126.html","https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.html","https://www.cve.org/CVERecord?id=CVE-2020-35478"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.35.1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-35477","published":"2020-12-18T08:15:00","updated_at":"2025-07-11T07:45:14.165865+00:00","description":"\nMediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in\nsome situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main\nPage, visits a log entry on Special:Log, and toggles the \"Change visibility\nof selected log entries\" checkbox (or a tags checkbox) next to it, there is\na redirection to the main page's action=historysubmit (instead of the\ndesired behavior in which a revision-deletion form appears).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T205908","https://lists.wikimedia.org/pipermail/wikitech-l/2020-December/094126.html","https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.html","https://www.cve.org/CVERecord?id=CVE-2020-35477"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.35.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-35475","published":"2020-12-18T08:15:00","updated_at":"2025-07-11T07:45:14.165865+00:00","description":"\nIn MediaWiki before 1.35.1, the messages userrights-expiry-current and\nuserrights-expiry-none can contain raw HTML. XSS can happen when a user\nvisits Special:UserRights but does not have rights to change all\nuserrights, and the table on the left side has unchangeable groups in it.\n(The right column with the changeable groups is not affected and is escaped\ncorrectly.)","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T268917","https://lists.wikimedia.org/pipermail/wikitech-l/2020-December/094126.html","https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.html","https://www.cve.org/CVERecord?id=CVE-2020-35475"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.35.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-35474","published":"2020-12-18T08:15:00","updated_at":"2025-07-11T07:45:10.155810+00:00","description":"\nIn MediaWiki before 1.35.1, the combination of Html::rawElement and\nMessage::text leads to XSS because the definition of\nMediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so\nthat the output is raw HTML.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T268894","https://lists.wikimedia.org/pipermail/wikitech-l/2020-December/094126.html","https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.html","https://www.cve.org/CVERecord?id=CVE-2020-35474"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.35.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-28052","published":"2020-12-18T01:15:00","updated_at":"2026-03-03T16:11:48.272727+00:00","description":"\nAn issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and\n1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect\ndata when checking the password, allowing incorrect passwords to indicate\nthey were matching with previously hashed ones that were different.","ubuntu_description":"","notes":[{"author":"hlibk","note":"Only affected 1.65 and 1.66. Patched in 1.67."}],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/bcgit/bc-java/wiki/CVE-2020-28052","https://www.synopsys.com/blogs/software-security/cve-2020-28052-bouncy-castle/","https://www.cve.org/CVERecord?id=CVE-2020-28052"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=977683"],"patches":{"bouncycastle":["upstream: https://github.com/bcgit/bc-java/commit/97578f9b7ed277e6ecb58834e85e3d18385a4219"]},"tags":{},"packages":[{"name":"bouncycastle","source":"https://ubuntu.com/security/cve?package=bouncycastle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bouncycastle","debian":"https://tracker.debian.org/pkg/bouncycastle","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.67","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":43840,"limit":20,"total_results":79316}