Candidate: CVE-2019-19617 PublicDate: 2019-12-06 03:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19617 https://github.com/phpmyadmin/phpmyadmin/commit/1119de642b136d20e810bb20f545069a01dd7cc9 https://github.com/phpmyadmin/phpmyadmin/compare/RELEASE_4_9_1...RELEASE_4_9_2 https://www.phpmyadmin.net/news/2019/11/22/phpmyadmin-492-released/ https://ubuntu.com/security/notices/USN-4639-1 Description: phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_phpmyadmin: upstream_phpmyadmin: released (4:4.9.2+dfsg1-1) precise/esm_phpmyadmin: DNE trusty_phpmyadmin: ignored (out of standard support) trusty/esm_phpmyadmin: needed xenial_phpmyadmin: ignored (end of standard support, was needed) bionic_phpmyadmin: released (4:4.6.6-5ubuntu0.5) disco_phpmyadmin: ignored (reached end-of-life) eoan_phpmyadmin: DNE focal_phpmyadmin: not-affected (4:4.9.2+dfsg1-1) groovy_phpmyadmin: not-affected (4:4.9.2+dfsg1-1) hirsute_phpmyadmin: not-affected (4:4.9.2+dfsg1-1) impish_phpmyadmin: not-affected (4:4.9.2+dfsg1-1) jammy_phpmyadmin: not-affected (4:4.9.2+dfsg1-1) devel_phpmyadmin: not-affected (4:4.9.2+dfsg1-1)