[Git][security-tracker-team/security-tracker][master] new cakephp issue

Moritz Muehlenhoff jmm at debian.org
Thu Jul 2 15:29:13 BST 2020



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8c134e11 by Moritz Muehlenhoff at 2020-07-02T16:28:53+02:00
new cakephp issue
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -213,7 +213,7 @@ CVE-2020-15402
 CVE-2020-15401 (IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privile ...)
 	NOT-FOR-US: IOBit Malware Fighter Pro
 CVE-2020-15400 (CakePHP before 4.0.6 mishandles CSRF token generation. This might be r ...)
-	TODO: check
+	- cakephp <unfixed>
 CVE-2020-15399
 	RESERVED
 CVE-2020-15398
@@ -19716,7 +19716,7 @@ CVE-2020-8026
 CVE-2020-8025
 	RESERVED
 CVE-2020-8024 (A Incorrect Default Permissions vulnerability in the packaging of hyla ...)
-	NOTE: Duplicate of CVE-2020-15397 / CVE-2020-15396, gonna ping SuSE for rejects
+	- hylafax <not-affected> (SuSE-specific packaging issue)
 CVE-2020-8023
 	RESERVED
 CVE-2020-8022 (A Incorrect Default Permissions vulnerability in the packaging of tomc ...)
@@ -34864,42 +34864,61 @@ CVE-2020-2220
 	RESERVED
 CVE-2020-2219
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2218
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2217
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2216
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2215
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2214
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2213
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2212
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2211
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2210
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2209
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2208
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2207
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2206
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2205
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2204
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2203
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2202
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2201
 	RESERVED
+	NOT-FOR-US: Jenkins plugin
 CVE-2020-2200 (Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the ...)
 	NOT-FOR-US: Jenkins plugin
 CVE-2020-2199 (Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier do ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8c134e1170f5cae667a915d753e23700cc2b2272

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8c134e1170f5cae667a915d753e23700cc2b2272
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200702/67c5c5c3/attachment.html>


More information about the debian-security-tracker-commits mailing list