Red Hat Pagure 5.2

CPE Details

Red Hat Pagure 5.2
5.2
2019-09-19
12h07 +00:00
2019-09-19
12h07 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:redhat:pagure:5.2:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

pagure

Version

5.2

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2019-11556 2020-09-25 03h56 +00:00 Pagure before 5.6 allows XSS via the templates/blame.html blame view.
6.1
Moyen
CVE-2019-7628 2019-02-08 02h00 +00:00 Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users. This issue is found in the API token expiration reminder cron job in files/api_key_expire_mail.py; disabling that job is also a viable solution. (E-mailing a substring of the API key was an attempted, but rejected, solution.)
5.9
Moyen