Bug 1183360 - (CVE-2020-13936) VUL-0: CVE-2020-13936: velocity: arbitrary code execution when attacker is able to modify templates
(CVE-2020-13936)
VUL-0: CVE-2020-13936: velocity: arbitrary code execution when attacker is ab...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Fridrich Strba
Security Team bot
https://smash.suse.de/issue/279452/
CVSSv3.1:SUSE:CVE-2020-13936:8.8:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-03-11 09:18 UTC by Alexander Bergmann
Modified: 2022-10-11 13:21 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Pascal Arlt 2021-03-11 14:28:58 UTC
We discussed this during our planning meeting and came to the conclusion that there is no action needed from the SUMA side since we don't actually ship this package it's just a build requirement.
Comment 3 OBSbugzilla Bot 2021-03-12 09:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (1183360) was mentioned in
https://build.opensuse.org/request/show/878483 Factory / velocity
Comment 5 OBSbugzilla Bot 2021-03-12 16:30:12 UTC
This is an autogenerated message for OBS integration:
This bug (1183360) was mentioned in
https://build.opensuse.org/request/show/878595 Factory / velocity
Comment 6 Swamp Workflow Management 2021-03-19 14:17:24 UTC
openSUSE-SU-2021:0447-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1183360
CVE References: CVE-2020-13936
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    velocity-1.7-lp152.5.3.1
Comment 7 Fridrich Strba 2022-04-07 09:50:57 UTC
fixed
Comment 10 Swamp Workflow Management 2022-10-11 13:21:32 UTC
SUSE-SU-2022:3560-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1183360,1202932,1203149,1203153,1203154,1203158
CVE References: CVE-2020-13936,CVE-2022-25857,CVE-2022-38749,CVE-2022-38750,CVE-2022-38751,CVE-2022-38752
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for SUSE Manager Server 4.1 (src):    snakeyaml-1.31-150200.12.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.