{"cves":[{"id":"CVE-2017-15594","published":"2017-10-18T08:29:00","updated_at":"2025-08-25T22:27:15.658249+00:00","description":"\nAn issue was discovered in Xen through 4.9.x allowing x86 SVM PV guest OS\nusers to cause a denial of service (hypervisor crash) or gain privileges\nbecause IDT settings are mishandled during CPU hotplugging.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-244.html","https://www.cve.org/CVERecord?id=CVE-2017-15594"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.6.4-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15593","published":"2017-10-18T08:29:00","updated_at":"2025-08-25T22:27:10.961026+00:00","description":"\nAn issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users\nto cause a denial of service (memory leak) because reference counts are\nmishandled.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-242.html","https://www.cve.org/CVERecord?id=CVE-2017-15593"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.6.4-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15592","published":"2017-10-18T08:29:00","updated_at":"2025-08-25T22:27:10.961026+00:00","description":"\nAn issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS\nusers to cause a denial of service (hypervisor crash) or possibly gain\nprivileges because self-linear shadow mappings are mishandled for\ntranslated guests.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-243.html","https://www.cve.org/CVERecord?id=CVE-2017-15592"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.6.4-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15591","published":"2017-10-18T08:29:00","updated_at":"2025-08-25T22:27:10.961026+00:00","description":"\nAn issue was discovered in Xen 4.5.x through 4.9.x allowing attackers (who\ncontrol a stub domain kernel or tool stack) to cause a denial of service\n(host OS crash) because of a missing comparison (of range start to range\nend) within the DMOP map/unmap implementation.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-238.html","https://www.cve.org/CVERecord?id=CVE-2017-15591"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"xenial","status":"released","description":"4.6.4-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15590","published":"2017-10-18T08:29:00","updated_at":"2025-08-25T22:27:10.961026+00:00","description":"\nAn issue was discovered in Xen through 4.9.x allowing x86 guest OS users to\ncause a denial of service (hypervisor crash) or possibly gain privileges\nbecause MSI mapping was mishandled.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-237.html","https://www.cve.org/CVERecord?id=CVE-2017-15590"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.6.4-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15589","published":"2017-10-18T08:29:00","updated_at":"2025-08-25T22:27:10.961026+00:00","description":"\nAn issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS\nusers to obtain sensitive information from the host OS (or an arbitrary\nguest OS) because intercepted I/O operations can cause a write of data from\nuninitialized hypervisor stack memory.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-239.html","https://www.cve.org/CVERecord?id=CVE-2017-15589"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"bionic","status":"released","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.6.4-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15588","published":"2017-10-18T08:29:00","updated_at":"2025-08-25T22:27:10.961026+00:00","description":"\nAn issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users\nto execute arbitrary code on the host OS because of a race condition that\ncan cause a stale TLB entry.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-241.html","https://www.cve.org/CVERecord?id=CVE-2017-15588"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.6.4-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15587","published":"2017-10-18T08:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nAn integer overflow was discovered in pdf_read_new_xref_section in\npdf/pdf-xref.c in Artifex MuPDF 1.11.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://git.ghostscript.com/?p=mupdf.git;h=82df2631d7d0446b206ea6b434ea609b6c28b0e8","https://bugs.ghostscript.com/show_bug.cgi?id=698605 (not public)","https://nandynarwhals.org/CVE-2017-15587/","https://www.cve.org/CVERecord?id=CVE-2017-15587"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=879055"],"patches":{"mupdf":[]},"tags":{},"packages":[{"name":"mupdf","source":"https://ubuntu.com/security/cve?package=mupdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mupdf","debian":"https://tracker.debian.org/pkg/mupdf","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.11+ds1-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.9a+ds1-4+deb9u1build0.17.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.12.0+ds1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15577","published":"2017-10-18T02:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nRedmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of\nwiki links, which allows remote attackers to obtain sensitive information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.redmine.org/issues/23793 (private)","https://www.redmine.org/issues/23793","https://www.cve.org/CVERecord?id=CVE-2017-15577"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"5.0.2-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"3.3.1-4+deb9u1build0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"5.0.2-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15576","published":"2017-10-18T02:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nRedmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering\nin activity views, which allows remote attackers to obtain sensitive\ninformation.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.redmine.org/issues/23803 (private)","https://www.redmine.org/issues/23803","https://www.cve.org/CVERecord?id=CVE-2017-15576"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"3.3.1-4+deb9u1build0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15575","published":"2017-10-18T02:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nIn Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check\nfor whether the Repository module is enabled in a project's settings, which\nmight allow remote attackers to obtain sensitive differences information or\npossibly have unspecified other impact.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.redmine.org/issues/24307 (private)","https://www.redmine.org/issues/24307","https://www.cve.org/CVERecord?id=CVE-2017-15575"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"3.3.1-4+deb9u1build0.17.10.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15574","published":"2017-10-18T02:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nIn Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by\nusing an SVG document as an attachment.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.redmine.org/issues/24199 (private)","https://www.redmine.org/issues/24199","https://www.cve.org/CVERecord?id=CVE-2017-15574"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"3.3.1-4+deb9u1build0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15573","published":"2017-10-18T02:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nIn Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup\nis mishandled in wiki content.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.redmine.org/issues/25503 (private)","https://www.redmine.org/issues/25503","https://www.cve.org/CVERecord?id=CVE-2017-15573"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"3.3.1-4+deb9u1build0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3.1-4+deb9u1, 3.4.2-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15572","published":"2017-10-18T02:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nIn Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain\nsensitive information (password reset tokens) by reading a Referer log,\nbecause account/lost_password does not use a redirect.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.redmine.org/issues/24416 (private)","https://www.redmine.org/issues/24416","https://www.cve.org/CVERecord?id=CVE-2017-15572"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"3.3.1-4+deb9u1build0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3.3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"5.0.2-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"5.0.2-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15571","published":"2017-10-18T02:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nIn Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS\nexists in app/views/issues/_list.html.erb via crafted column data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.redmine.org/issues/27186 (private)","https://github.com/redmine/redmine/commit/273dd9cb3bcfb1e0a0b90570b3b34eafa07d67aa","https://www.redmine.org/issues/27186","https://www.cve.org/CVERecord?id=CVE-2017-15571"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"3.3.1-4+deb9u1build0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15570","published":"2017-10-18T02:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nIn Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS\nexists in app/views/timelog/_list.html.erb via crafted column data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.redmine.org/issues/27186 (private)","https://github.com/redmine/redmine/commit/1a0976417975a128b0a932ba1552c37e9414953b","https://www.redmine.org/issues/27186","https://www.cve.org/CVERecord?id=CVE-2017-15570"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"3.3.1-4+deb9u1build0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15569","published":"2017-10-18T02:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nIn Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS\nexists in app/helpers/queries_helper.rb via a multi-value field with a\ncrafted value that is mishandled during rendering of an issue list.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.redmine.org/issues/27186 (private)","https://github.com/redmine/redmine/commit/56c8ee0440d8555aa7822d947ba9091c8a791508","https://www.redmine.org/issues/27186","https://www.cve.org/CVERecord?id=CVE-2017-15569"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"3.3.1-4+deb9u1build0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15568","published":"2017-10-18T02:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nIn Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS\nexists in app/helpers/application_helper.rb via a multi-value field with a\ncrafted value that is mishandled during rendering of issue history.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.redmine.org/issues/27186 (private)","https://github.com/redmine/redmine/commit/94f7cfbf990028348b9262578acbc53a94fce448","https://www.redmine.org/issues/27186","https://www.cve.org/CVERecord?id=CVE-2017-15568"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"3.3.1-4+deb9u1build0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.4-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-10515","published":"2017-10-18T02:29:00","updated_at":"2025-08-26T11:53:50.029867+00:00","description":"\nIn Redmine before 3.2.3, there are stored XSS vulnerabilities affecting\nTextile and Markdown text formatting, and project homepages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.redmine.org/projects/redmine/wiki/Security_Advisories","https://www.cve.org/CVERecord?id=CVE-2016-10515"],"bugs":[""],"patches":{"redmine":[]},"tags":{},"packages":[{"name":"redmine","source":"https://ubuntu.com/security/cve?package=redmine","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redmine","debian":"https://tracker.debian.org/pkg/redmine","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"5.0.2-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"3.2.3-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.2.3-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.2.3-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.2.3-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.2.3-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.2.3-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.2.3-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.3-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"5.0.2-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-7120","published":"2017-10-18T00:00:00","updated_at":"2025-08-25T22:37:08.612115+00:00","description":"\nAn issue was discovered in certain Apple products. iOS before 11 is\naffected. Safari before 11 is affected. iCloud before 7.0 on Windows is\naffected. iTunes before 12.7 on Windows is affected. tvOS before 11 is\naffected. The issue involves the \"WebKit\" component. It allows remote\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption and application crash) via a crafted web site.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2017-0008.html","https://ubuntu.com/security/notices/USN-3460-1","https://www.cve.org/CVERecord?id=CVE-2017-7120"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"jammy","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.18.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.18.0-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2.18.0-0ubuntu0.17.04.2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.18.0-2","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3460-1"],"notices":[{"id":"USN-3460-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2017-10-23T15:05:54.903190","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"webkit2gtk","version":"2.18.0-0ubuntu0.16.04.2","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.18.0-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.18.0-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.18.0-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.18.0-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.18.0-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.18.0-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.18.0-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.18.0-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.18.0-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.0-0ubuntu0.16.04.2","pocket":"security"}],"zesty":[{"name":"webkit2gtk","version":"2.18.0-0ubuntu0.17.04.2","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.18.0-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.0-0ubuntu0.17.04.2"},{"name":"libwebkit2gtk-4.0-37","version":"2.18.0-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.0-0ubuntu0.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-7087","CVE-2017-7089","CVE-2017-7090","CVE-2017-7091","CVE-2017-7092","CVE-2017-7093","CVE-2017-7095","CVE-2017-7096","CVE-2017-7098","CVE-2017-7100","CVE-2017-7102","CVE-2017-7104","CVE-2017-7107","CVE-2017-7109","CVE-2017-7111","CVE-2017-7117","CVE-2017-7120"]}]}],"offset":54980,"limit":20,"total_results":79316}