Skip to content

Releases: csaf-tools/CVRF-CSAF-Converter

Release v1.0.0

02 May 12:06
140c145
Compare
Choose a tag to compare

Version 1.0.0 release, all issues labeled with acceptance are completed.

Release candidate 2: Fixed XXE vulnerability

14 Mar 12:16
ff20a6c
Compare
Choose a tag to compare

RC 2 is fixing an XXE (XML eXternal Entities) vulnerability. This can lead to the inclusion of arbitrary (local) file content into the generated output document. An attacker can exploit this to disclose information from the system running the converter by using specially crafted XML input files.

This issue is being tracked as CVE-2022-27193.

Release candidate v1.0.0-rc1

28 Feb 16:24
Compare
Choose a tag to compare
Pre-release

Pre-release (release candidate) for handover of this project:

#12