rainloop (1.12.1-2+deb10u1) buster-security; urgency=high * Non-maintainer upload by the LTS Security Team. * CVE-2019-13389: RainLoop Webmail lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header. * CVE-2022-29360: RainLoop's Email Viewer allows XSS via a crafted email message (closes: #1004548). -- Guilhem Moulin Sat, 27 May 2023 22:20:58 +0200 rainloop (1.12.1-2) unstable; urgency=medium * Install default config files to /etc (Closes: #920674) * Remove symlinks to default config files on uninstall -- Daniel Ring Wed, 06 Feb 2019 23:59:52 -0800 rainloop (1.12.1-1) unstable; urgency=medium * New upstream release -- Daniel Ring Sun, 13 Jan 2019 00:30:06 -0800 rainloop (1.11.1-2) unstable; urgency=medium * Depend on php-nrk-predis instead of libphp-predis (Closes: #917605) * Update default webserver config files for PHP-FPM 7.3 -- Daniel Ring Sat, 05 Jan 2019 01:06:30 -0800 rainloop (1.11.1-1) unstable; urgency=medium * Initial release (Closes: #861581) -- Daniel Ring Mon, 17 Dec 2018 20:42:00 -0700