Debian Security Advisory

DSA-4798-1 spip -- security update

Date Reported:
25 Nov 2020
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CVE-2020-28984.
More information:

It was discovered that SPIP, a website engine for publishing, did not correctly validate its input. This would allow authenticated users to execute arbitrary code.

For the stable distribution (buster), this problem has been fixed in version 3.2.4-1+deb10u3.

We recommend that you upgrade your spip packages.

For the detailed security status of spip please refer to its security tracker page at: