Debian Security Advisory
DSA-4798-1 spip -- security update
- Date Reported:
- 25 Nov 2020
- Affected Packages:
- spip
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2020-28984.
- More information:
-
It was discovered that SPIP, a website engine for publishing, did not correctly validate its input. This would allow authenticated users to execute arbitrary code.
For the stable distribution (buster), this problem has been fixed in version 3.2.4-1+deb10u3.
We recommend that you upgrade your spip packages.
For the detailed security status of spip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/spip