Bug#961298: jodd: CVE-2018-21234: Potential vulnerability in JSON deserialization

2020-05-30 Thread Emmanuel Bourg
Control: severity -1 important Le 22/05/2020 à 22:51, Salvatore Bonaccorso a écrit : > The following vulnerability was published for jodd. I'm filling it as > RC severity since altough one might dispute the severity for the issue > itself, it looks that in Debian there was ever only one upload of

Processed: Re: Bug#961298: jodd: CVE-2018-21234: Potential vulnerability in JSON deserialization

2020-05-30 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #961298 [src:jodd] jodd: CVE-2018-21234: Potential vulnerability in JSON deserialization Severity set to 'important' from 'grave' -- 961298: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=961298 Debian Bug Tracking System Contact ow...

Bug#961298: jodd: CVE-2018-21234: Potential vulnerability in JSON deserialization

2020-05-22 Thread Salvatore Bonaccorso
Source: jodd Version: 3.8.6-1 Severity: grave Tags: security upstream Justification: user security hole Forwarded: https://github.com/oblac/jodd/issues/628 Hi, The following vulnerability was published for jodd. I'm filling it as RC severity since altough one might dispute the severity for the is