You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"advisory": "ampache 4.0.0:\r\n* Resolves CVE-2019-12385 for the SQL Injection\r\n* Resolves CVE-2019-12386 for the persistent XSS\r\n* Resolves NS-18-046 Multiple Reflected Cross-site Scripting Vulnerabilities in Ampache 3.9.0",
5
-
"cve": "CVE-2019-12385, CVE-2019-12386",
6
-
"id": "pyup.io-37863",
7
-
"specs": [
8
-
"<4.0.0"
9
-
],
10
-
"v": "<4.0.0"
11
-
}
12
-
],
13
2
"django": [
14
3
{
15
4
"advisory": "The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \\x08javascript: URL.",
"advisory": "Zulip 2.1.2 includes a corrected fix for CVE-2019-19775 (the original fix was affected by an unfixed security bug in Python's urllib, CVE-2015-2104). It also adds authentication for redis and memcached even in configurations where these are running on localhost, for add hardening against attacks from malicious processes running on the Zulip server.",
51
-
"cve": "CVE-2019-19775,CVE-2015-2104",
52
-
"id": "pyup.io-38114",
53
-
"specs": [
54
-
"<2.1.2"
55
-
],
56
-
"v": "<2.1.2"
57
-
},
58
-
{
59
-
"advisory": "Zulip 2.1.3 includes fixes for:\r\n- CVE-2020-9444: Prevent reverse tabnapping attacks. \r\n- CVE-2020-9445: Remove unused and insecure modal_link feature. \r\n- CVE-2020-10935: Fix XSS vulnerability in local link rewriting.",
0 commit comments