FS#71558 - [geckodriver] [Security] cross-site request forgery (CVE-2020-15660)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Tuesday, 20 July 2021, 15:47 GMT
Last edited by Jonas Witschel (diabonas) - Sunday, 25 July 2021, 12:42 GMT
Opened by Jonas Witschel (diabonas) - Tuesday, 20 July 2021, 15:47 GMT
Last edited by Jonas Witschel (diabonas) - Sunday, 25 July 2021, 12:42 GMT
|
Details
Summary
======= The package geckodriver is vulnerable to cross-site request forgery via CVE-2020-15660. Guidance ======== Upgrading geckodriver to version 0.27.0 fixes the issue. References ========== https://security.archlinux.org/AVG-2180 https://github.com/mozilla/geckodriver/releases/tag/v0.27.0 |
This task depends upon
Closed by Jonas Witschel (diabonas)
Sunday, 25 July 2021, 12:42 GMT
Reason for closing: Fixed
Additional comments about closing: geckodriver 0.29.1-1
Sunday, 25 July 2021, 12:42 GMT
Reason for closing: Fixed
Additional comments about closing: geckodriver 0.29.1-1