Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1251436

Bug#1108508: bookworm-pu: package python-flask-cors/3.0.10-2+deb12u1

From Daniel Leidert <dleidert@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.devel.release
Subject Bug#1108508: bookworm-pu: package python-flask-cors/3.0.10-2+deb12u1
Date 2025-06-30 03:30 +0200
Message-ID <L3bvj-e7Us-1@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Package: release.debian.org
Severity: normal
Tags: bookworm
X-Debbugs-Cc: python-flask-cors@packages.debian.org
Control: affects -1 + src:python-flask-cors
User: release.debian.org@packages.debian.org
Usertags: pu

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

[ Reason ]
There are multiple vulnerabilities in python-flask-cors which have been fixed
in Sid/Trixie and in LTS, but not in Bookworm yet. This upload attempts to
close them for stable as well, and to offer a clean upgrade path for LTS users.

[ Impact ]
If the issues are not fixed, users of Debian Bookworm will continue to be
vulnerable. And users of LTS might become vulnerable when upgrading to
Bookworm.

[ Tests ]
The package uses autopkgtest to run the upstream testsuite. The tests are
successful.

[ Risks ]
There are the usual risks of regression and unexpected behavior. However, the
upstream testuite is successful and the changes have already been applied to
LTS without issues.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
The patch for CVE-2024-1681 to clean request.path before logging it is quite
trivial.

The patch for CVE-2024-6839 fixes a regex pattern matching and is covered by a
newly introduced test.

The patch for CVE-2024-6844 replaces the usage of urllib's unquote_plus to
unquote to avoid unintended behavior. New tests have been added to cover the
function.

The patch for CVE-2024-6866 changes a few functions to allow for case-sensitive
and case-insensitive matching where appropriate. New tests have been added as
well.

[ Other info ]
n/a

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmhh6A8ACgkQS80FZ8KW
0F2GIhAAlABzeYmnNksIdM//BWaXqFuxx4SUnT5mtkf09ov9Zu+kCPucoMmNsS7Z
ufIEc6DT9y+cIMshrIu+YEYb7buyDLWEEz7m2CjS6EiTxPrXLEOJLGSs7zzgkbcF
kHDcUFJw/rKREWy39Y4de/TAW0vwtQ2TSldAGtqOKLoVs9ehB0g1ABKQiWsNiXHn
45gWm6G3flVVynhcw40NMNtCvBErO/0IeiVStlckmt4nnQs0lXvohmrX1MFnS+6u
PjYJFWPyCofJhwerpBDE3ihNTD9922uieHBm8L3OffX2nApRYdY6AhToSO679I3i
4iAvLG2xEHb+ZhKciutDArN8MBuKY/Rsmza5eYyCnY9yzv+/m2tyxb8nmu7h4Pdp
HLIwWLwT9LaeYFYbMRJlpeQaBXYnYMOr7EB0GRjNAxC6+CeSFZrrNuoHtVnZuWg3
niu42V1qELeMbQJaVhVcTUr43/KAi19EyUqO0KHiJ3r+vIq7jLw47LUPDLaz1T6d
oUq+6+erdPyURYMSCHFR9SylDcu37RMQDC02hqUFuF6YlvWheMGWzsAJkQPm3cTq
VYzFZej77GPR3mNCvJkSiEzoZ+69en5vdS+YoIV2rIo7NGQH69tUT6iXeA/iJ4f5
nBdWnuHT5GLgLr6oTQiSaD3ibwOERCJkk4ldtWokS5J9nWDO5s0=
=5bkH
-----END PGP SIGNATURE-----

Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#1108508: bookworm-pu: package python-flask-cors/3.0.10-2+deb12u1 Daniel Leidert <dleidert@debian.org> - 2025-06-30 03:30 +0200
  Bug#1108508: bookworm-pu: package python-flask-cors/3.0.10-2+deb12u1 Jonathan Wiltshire <jmw@debian.org> - 2025-07-07 10:30 +0200
  Bug#1108508: python-flask-cors 3.0.10-2+deb12u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2025-08-27 21:20 +0200

csiph-web