Bug 2335749
Summary: | CVE-2024-56332 conky: Next.js Vulnerable to Denial of Service (DoS) with Server Actions [epel-8] | ||
---|---|---|---|
Product: | [Fedora] Fedora EPEL | Reporter: | Avinash Hanwate <ahanwate> |
Component: | conky | Assignee: | Miroslav Lichvar <mlichvar> |
Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | epel8 | CC: | jonathan, mlichvar, moceap |
Target Milestone: | --- | Keywords: | Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | {"flaws": ["3e94bde1-b5a7-4228-b6c6-4e6195eefec2"]} | ||
Fixed In Version: | Doc Type: | No Doc Update | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2025-01-06 10:22:04 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 2335479 |
Description
Avinash Hanwate
2025-01-06 04:03:05 UTC
The conky upstream tarball includes the source code of the upstream website, which seems to be using next.js, but that is not included in the rpms we build for Fedora. |