[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-22 Thread Mathew Hodson
** Information type changed from Public to Public Security ** No longer affects: mongodb (Ubuntu) ** Changed in: mongodb (Ubuntu Trusty) Importance: Undecided => Low ** Changed in: mongodb (Ubuntu Bionic) Importance: Undecided => Low ** Changed in: mongodb (Ubuntu Focal) Importance: Un

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-13 Thread Heather Lemon
** Patch removed: "CVE-2019-2386-focal-20210702.debdiff" https://bugs.launchpad.net/ubuntu/+source/mongodb/+bug/1934518/+attachment/5508666/+files/CVE-2019-2386-focal-20210702.debdiff ** Patch removed: "CVE-2019-2386-focal-20210706.debdiff" https://bugs.launchpad.net/ubuntu/+source/mongodb

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-07 Thread Alex Murray
Ah I see, python-requests is not in focal anymore - all good. Thanks again. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1934518 Title: improper invalidation of authorization sessions To manage n

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-07 Thread Alex Murray
Was it intentional to remove python-requests from Build-Depends for focal> -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1934518 Title: improper invalidation of authorization sessions To manage no

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-06 Thread Heather Lemon
redo patch for bionic add CVE tags updated dch and quilt patch headers ** Patch added: "CVE-2019-2386-bionic-20210706.debdiff" https://bugs.launchpad.net/ubuntu/+source/mongodb/+bug/1934518/+attachment/5509448/+files/CVE-2019-2386-bionic-20210706.debdiff -- You received this bug notification

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-06 Thread Heather Lemon
updated changelog and quilt headers to add CVE# ** Patch added: "CVE-2019-2386-focal-20210706.debdiff" https://bugs.launchpad.net/ubuntu/+source/mongodb/+bug/1934518/+attachment/5509445/+files/CVE-2019-2386-focal-20210706.debdiff -- You received this bug notification because you are a member

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-06 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: mongodb (Ubuntu Focal) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1934518 Title

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-06 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: mongodb (Ubuntu Bionic) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1934518 Titl

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-06 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: mongodb (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1934518 Title: i

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-06 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: mongodb (Ubuntu Trusty) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1934518 Titl

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-06 Thread Heather Lemon
** Tags added: bug security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1934518 Title: improper invalidation of authorization sessions To manage notifications about this bug go to: https://bugs.

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-02 Thread Ubuntu Foundations Team Bug Bot
The attachment "CVE-2019-2386-bionic-20210702.debdiff" seems to be a debdiff. The ubuntu-sponsors team has been subscribed to the bug report so that they can review and hopefully sponsor the debdiff. If the attachment isn't a patch, please remove the "patch" flag from the attachment, remove the "

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-02 Thread Heather Lemon
cve-2019-2386 focal improper invalidation of authorization sessions allows an authenticated user’s session to persist and become conflated with new accounts. ** Patch added: "CVE-2019-2386-focal-20210702.debdiff" https://bugs.launchpad.net/ubuntu/+source/mongodb/+bug/1934518/+attachment/550866

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-02 Thread Heather Lemon
cve-2019-2386 bionic improper invalidation of authorization sessions allows an authenticated user’s session to persist and become conflated with new accounts. ** Patch added: "CVE-2019-2386-bionic-20210702.debdiff" https://bugs.launchpad.net/ubuntu/+source/mongodb/+bug/1934518/+attachment/5508

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-02 Thread Heather Lemon
** Tags removed: security ** Tags added: ubuntu-security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1934518 Title: improper invalidation of authorization sessions To manage notifications about

[Bug 1934518] Re: improper invalidation of authorization sessions

2021-07-02 Thread Heather Lemon
** Tags added: security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1934518 Title: improper invalidation of authorization sessions To manage notifications about this bug go to: https://bugs.laun