{"update": {"autokarma": true, "autotime": false, "stable_karma": 3, "stable_days": 0, "unstable_karma": -3, "require_bugs": true, "require_testcases": true, "display_name": "", "notes": "Security fix for CVE-2018-19044, CVE-2018-19045, CVE-2018-19046, CVE-2018-19115\n", "type": "security", "status": "stable", "request": null, "severity": "high", "suggest": "unspecified", "locked": false, "pushed": true, "critpath": false, "critpath_groups": null, "close_bugs": true, "date_submitted": "2018-11-26 18:15:32", "date_modified": "2018-12-10 18:54:25", "date_approved": null, "date_testing": "2018-11-27 05:13:12", "date_stable": "2018-12-11 02:42:14", "alias": "FEDORA-2018-3fbc181b3e", "test_gating_status": "ignored", "from_tag": null, "date_pushed": "2018-12-11 02:42:14", "meets_testing_requirements": true, "url": "https://bodhi.fedoraproject.org/updates/FEDORA-2018-3fbc181b3e", "title": "keepalived-2.0.10-1.fc29", "version_hash": "b7bd502cec7ab456838cbe3bf2ccbc944a26fdc4", "release": {"name": "F29", "long_name": "Fedora 29", "version": "29", "id_prefix": "FEDORA", "branch": "f29", "dist_tag": "f29", "stable_tag": "f29-updates", "testing_tag": "f29-updates-testing", "candidate_tag": "f29-updates-candidate", "pending_signing_tag": "f29-signing-pending", "pending_testing_tag": "f29-updates-testing-pending", "pending_stable_tag": "f29-updates-pending", "override_tag": "f29-override", "mail_template": "fedora_errata_template", "state": "archived", "composed_by_bodhi": true, "create_automatic_updates": false, "package_manager": "dnf", "testing_repository": "updates-testing", "released_on": null, "eol": null, "setting_status": null}, "user": {"id": 439, "name": "rohara", "email": "rohara@redhat.com", "avatar": "https://seccdn.libravatar.org/avatar/66871fbef893b522e90f5f2fce079911dc62dc3fa285c371f186ff2a6b4d285f?s=24&d=retro", "openid": "rohara.id.fedoraproject.org", "groups": [{"name": "packager"}, {"name": "gitcluster"}, {"name": "gitfence"}, {"name": "gitgfs1-utils"}, {"name": "signed_fpca"}, {"name": "gitresource-agents"}, {"name": "svncorosync"}, {"name": "fedora-contributor"}, {"name": "gitgnbd"}, {"name": "gitpiranha"}, {"name": "gitdlm"}, {"name": "ipausers"}, {"name": "svnopenais"}, {"name": "gitfence-agents"}, {"name": "fedorabugs"}, {"name": "gitrgmanager"}, {"name": "gitgfs2-utils"}, {"name": "gitfoghorn"}]}, "comments": [{"id": 867070, "karma": 0, "karma_critpath": 0, "text": "This update has been submitted for testing by rohara. ", "timestamp": "2018-11-26 18:15:32", "update_id": 127432, "user_id": 91, "bug_feedback": [], "testcase_feedback": [], "user": {"id": 91, "name": "bodhi", "email": null, "avatar": "https://apps.fedoraproject.org/img/icons/bodhi-24.png", "openid": "bodhi.id.fedoraproject.org", "groups": []}}, {"id": 867291, "karma": 0, "karma_critpath": 0, "text": "This update has been pushed to testing.", "timestamp": "2018-11-27 05:15:16", "update_id": 127432, "user_id": 91, "bug_feedback": [], "testcase_feedback": [], "user": {"id": 91, "name": "bodhi", "email": null, "avatar": "https://apps.fedoraproject.org/img/icons/bodhi-24.png", "openid": "bodhi.id.fedoraproject.org", "groups": []}}, {"id": 867371, "karma": 0, "karma_critpath": 0, "text": "hello rohara, thank you for your work!\ni assume you have mixed up CVE-2018-19047 with CVE-2018-19115 in the description at the top. CVE-2018-19047 concerns mPDF and is currently disputed:\n>> CVE-2018-19047: ** DISPUTED ** mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '> CVE-2018-19047: ** DISPUTED ** mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '> CVE-2018-19047: ** DISPUTED ** mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '> CVE-2018-19047: ** DISPUTED ** mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '> CVE-2018-19047: ** DISPUTED ** mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '> CVE-2018-19047: ** DISPUTED ** mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '> CVE-2018-19047: ** DISPUTED ** mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '> CVE-2018-19047: ** DISPUTED ** mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '> CVE-2018-19047: ** DISPUTED ** mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '