Bug ID | 1158801 |
---|---|
Summary | VUL-1: CVE-2019-19617: phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php. |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | Leap 15.1 |
Hardware | Other |
URL | https://smash.suse.de/issue/248488/ |
OS | Other |
Status | NEW |
Severity | Minor |
Priority | P5 - None |
Component | Security |
Assignee | chris@computersalat.de |
Reporter | wolfgang.frisch@suse.com |
QA Contact | security-team@suse.de |
Found By | Security Response Team |
Blocker | --- |
CVE-2019-19617 phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-19617 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-19617.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19617 https://github.com/phpmyadmin/phpmyadmin/commit/1119de642b136d20e810bb20f545069a01dd7cc9 https://github.com/phpmyadmin/phpmyadmin/compare/RELEASE_4_9_1...RELEASE_4_9_2 https://www.phpmyadmin.net/news/2019/11/22/phpmyadmin-492-released/