[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff jmm at debian.org
Fri Jul 3 11:04:34 BST 2020



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c8c28049 by Moritz Muehlenhoff at 2020-07-03T12:04:11+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -889,7 +889,7 @@ CVE-2020-15093
 CVE-2020-15092
 	RESERVED
 CVE-2020-15091 (TenderMint from version 0.33.0 and before version 0.33.6 allows block  ...)
-	TODO: check
+	NOT-FOR-US: TenderMint
 CVE-2020-15090
 	RESERVED
 CVE-2020-15089
@@ -903,7 +903,7 @@ CVE-2020-15086
 CVE-2020-15085 (In Saleor Storefront before version 2.10.3, request data used to authe ...)
 	NOT-FOR-US: Saleor Storefront
 CVE-2020-15084 (In express-jwt (NPM package) up and including version 5.3.3, the algor ...)
-	TODO: check
+	NOT-FOR-US: Node express-jwt
 CVE-2020-15083 (In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a ta ...)
 	NOT-FOR-US: PrestaShop
 CVE-2020-15082 (In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the das ...)
@@ -3171,9 +3171,9 @@ CVE-2020-14175
 CVE-2020-14174
 	RESERVED
 CVE-2020-14173 (The file upload feature in Atlassian Jira Server and Data Center in af ...)
-	TODO: check
+	NOT-FOR-US: Atlasstian
 CVE-2020-14172 (Affected versions of Atlassian Jira Server and Data Center allow remot ...)
-	TODO: check
+	NOT-FOR-US: Atlasstian
 CVE-2020-14171
 	RESERVED
 CVE-2020-14170
@@ -4568,7 +4568,7 @@ CVE-2020-13655
 CVE-2020-13654
 	RESERVED
 CVE-2020-13653 (An XSS vulnerability exists in the Webmail component of Zimbra Collabo ...)
-	TODO: check
+	NOT-FOR-US: Zimbra
 CVE-2020-13652 (An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 bef ...)
 	NOT-FOR-US: DigDash
 CVE-2020-13651 (An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 bef ...)
@@ -8276,7 +8276,7 @@ CVE-2020-12121
 CVE-2020-12120 (The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote ...)
 	NOT-FOR-US: PrestaShop
 CVE-2020-12119 (Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF ...)
-	TODO: check
+	NOT-FOR-US: Ledger Live
 CVE-2020-12118 (The keygen protocol implementation in Binance tss-lib before 1.2.0 all ...)
 	NOT-FOR-US: Binance tss-lib
 CVE-2020-12117 (Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allo ...)
@@ -11994,7 +11994,7 @@ CVE-2020-11076 (In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smu
 CVE-2020-11075 (In Anchore Engine version 0.7.0, a specially crafted container image m ...)
 	NOT-FOR-US: Anchore Engine
 CVE-2020-11074 (In PrestaShop from version 1.5.3.0 and before version 1.7.7.6, there i ...)
-	TODO: check
+	NOT-FOR-US: PrestaShop
 CVE-2020-11073 (In Autoswitch Python Virtualenv before version 0.16.0, a user who ente ...)
 	NOT-FOR-US: zsh-autoswitch-virtualenv
 CVE-2020-11072 (In SLP Validate (npm package slp-validate) before version 1.2.1, users ...)
@@ -19300,7 +19300,7 @@ CVE-2020-8190
 CVE-2020-8189
 	RESERVED
 CVE-2020-8188 (We have recently released new version of UniFi Protect firmware v1.13. ...)
-	TODO: check
+	NOT-FOR-US: UniFi Protect
 CVE-2020-8187
 	RESERVED
 CVE-2020-8186
@@ -19321,7 +19321,7 @@ CVE-2020-8181
 CVE-2020-8180 (A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a cod ...)
 	NOT-FOR-US: Nextcloud Talk
 CVE-2020-8179 (Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to ...)
-	TODO: check
+	NOT-FOR-US: Nextcloud Deck
 CVE-2020-8178
 	RESERVED
 CVE-2020-8177
@@ -19330,7 +19330,7 @@ CVE-2020-8177
 	NOTE: https://curl.haxx.se/docs/CVE-2020-8177.html
 	NOTE: https://github.com/curl/curl/commit/8236aba58542c5f89f1d41ca09d84579efb05e22 (7.71.0)
 CVE-2020-8176 (A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.6 ...)
-	TODO: check
+	NOT-FOR-US: koa-shopify-auth
 CVE-2020-8175
 	RESERVED
 CVE-2020-8174 [napi_get_value_string_*() allows various kinds of memory corruption]



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c8c28049df4b5a35c05bbc4d037e6c22e4456bfa

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c8c28049df4b5a35c05bbc4d037e6c22e4456bfa
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200703/2d8fae58/attachment.html>


More information about the debian-security-tracker-commits mailing list