From 8f897ee341aa3926626bb36688ebcbdd557ff716 Mon Sep 17 00:00:00 2001 From: Kent 'picat' Gruber Date: Wed, 14 Apr 2021 18:45:49 -0400 Subject: [PATCH 1/2] Add synthetic enterprise entry for CVE-2021-28156 --- .changelog/_795.txt | 3 +++ 1 file changed, 3 insertions(+) create mode 100644 .changelog/_795.txt diff --git a/.changelog/_795.txt b/.changelog/_795.txt new file mode 100644 index 000000000..3ab9a059b --- /dev/null +++ b/.changelog/_795.txt @@ -0,0 +1,3 @@ +```release-note:security +Parse endpoint URL to prevent requests from bypassing the audit log [CVE-2021-28156](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28156) +``` \ No newline at end of file From 78ce699787f0a9b1401453d972f5925fb1835fae Mon Sep 17 00:00:00 2001 From: Kent 'picat' Gruber Date: Wed, 14 Apr 2021 19:41:04 -0400 Subject: [PATCH 2/2] Add component name to entry Co-authored-by: Daniel Nephin --- .changelog/_795.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.changelog/_795.txt b/.changelog/_795.txt index 3ab9a059b..5c80d7924 100644 --- a/.changelog/_795.txt +++ b/.changelog/_795.txt @@ -1,3 +1,3 @@ ```release-note:security -Parse endpoint URL to prevent requests from bypassing the audit log [CVE-2021-28156](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28156) -``` \ No newline at end of file +audit-logging: Parse endpoint URL to prevent requests from bypassing the audit log [CVE-2021-28156](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28156) +```