Merge ~federicoquattrin/ubuntu-cve-tracker:fixed_CVVE_2023_46233 into ubuntu-cve-tracker:master

Proposed by Federico Quattrin
Status: Merged
Merged at revision: dbbe1e6a247bab9a02a1a1b29d906303f36e78f4
Proposed branch: ~federicoquattrin/ubuntu-cve-tracker:fixed_CVVE_2023_46233
Merge into: ubuntu-cve-tracker:master
Diff against target: 48 lines (+12/-10)
1 file modified
active/CVE-2023-46233 (+12/-10)
Reviewer Review Type Date Requested Status
Emilia Torino Approve
Review via email: mp+465022@code.launchpad.net

Commit message

updated information for CVE-2023-46233

Description of the change

updated information for CVE-2023-46233

To post a comment you must log in.
Revision history for this message
Emilia Torino (emitorino) wrote :

LGTM

review: Approve

Preview Diff

[H/L] Next/Prev Comment, [J/K] Next/Prev File, [N/P] Next/Prev Hunk
diff --git a/active/CVE-2023-46233 b/active/CVE-2023-46233
index 095833f..a45b017 100644
--- a/active/CVE-2023-46233
+++ b/active/CVE-2023-46233
@@ -1,9 +1,11 @@
1PublicDateAtUSN: 2023-10-25 21:15:00 UTC
1Candidate: CVE-2023-462332Candidate: CVE-2023-46233
2PublicDate: 2023-10-25 21:15:00 UTC3PublicDate: 2023-10-25 21:15:00 UTC
3References:4References:
4 https://github.com/brix/crypto-js/security/advisories/GHSA-xwcq-pm8m-c4vf5 https://github.com/brix/crypto-js/security/advisories/GHSA-xwcq-pm8m-c4vf
5 https://github.com/brix/crypto-js/commit/421dd538b2d34e7c24a5b72cc64dc2b9167db40a6 https://github.com/brix/crypto-js/commit/421dd538b2d34e7c24a5b72cc64dc2b9167db40a
6 https://www.cve.org/CVERecord?id=CVE-2023-462337 https://www.cve.org/CVERecord?id=CVE-2023-46233
8 https://ubuntu.com/security/notices/USN-6753-1
7Description:9Description:
8 crypto-js is a JavaScript library of crypto standards. Prior to version10 crypto-js is a JavaScript library of crypto standards. Prior to version
9 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in11 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in
@@ -22,21 +24,21 @@ Mitigation:
22Bugs:24Bugs:
23Priority: medium25Priority: medium
24Discovered-by:26Discovered-by:
25Assigned-to: federicoquattrin27Assigned-to:
26CVSS:28CVSS:
27 nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N [9.1 CRITICAL]29 nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N [9.1 CRITICAL]
2830
29Patches_cryptojs:31Patches_cryptojs:
30upstream_cryptojs: needs-triage32upstream_cryptojs: released (4.2.0)
31trusty_cryptojs: ignored (end of standard support)33trusty_cryptojs: ignored (end of standard support)
32xenial_cryptojs: ignored (end of standard support)34xenial_cryptojs: ignored (end of standard support)
33esm-apps/xenial_cryptojs: needs-triage35esm-apps/xenial_cryptojs: released (3.1.2+dfsg-2ubuntu0.16.04.1~esm1)
34bionic_cryptojs: ignored (end of standard support)36bionic_cryptojs: ignored (end of standard support)
35esm-apps/bionic_cryptojs: needs-triage37esm-apps/bionic_cryptojs: released (3.1.2+dfsg-2ubuntu0.18.04.1~esm1)
36focal_cryptojs: needs-triage38focal_cryptojs: released (3.1.2+dfsg-2ubuntu0.20.04.1)
37esm-apps/focal_cryptojs: needs-triage39esm-apps/focal_cryptojs: not-affected (3.1.2+dfsg-2ubuntu0.20.04.1)
38jammy_cryptojs: needs-triage40jammy_cryptojs: needed
39esm-apps/jammy_cryptojs: needs-triage41esm-apps/jammy_cryptojs: released (3.1.2+dfsg-3ubuntu0.22.04.1~esm1)
40lunar_cryptojs: ignored (end of life, was needs-triage)42lunar_cryptojs: ignored (end of life, was needs-triage)
41mantic_cryptojs: needs-triage43mantic_cryptojs: needed
42devel_cryptojs: needs-triage44devel_cryptojs: needed

Subscribers

People subscribed via source and target branches