[Git][security-tracker-team/security-tracker][master] Remove notes from CVE-2020-10747

Salvatore Bonaccorso carnil at debian.org
Wed Jun 17 18:38:48 BST 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
18cc2dda by Salvatore Bonaccorso at 2020-06-17T19:35:51+02:00
Remove notes from CVE-2020-10747

Red Hat has withdrawn the assigned CVE and REJECTED it because as
outlined in <https://bugzilla.redhat.com/show_bug.cgi?id=1810160> the
issue is not crossing boundaries and the corresponding update from
<https://pagure.io/freeipa/issue/8326> is considered a configuration
tightening.

In any case the CVE is REJECTED from the assigning CNA (Red Hat) and
will be marked as such soon. Remove the unneded references.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9954,14 +9954,8 @@ CVE-2020-10749 (A vulnerability was found in all versions of containernetworking
 	NOTE: https://github.com/containernetworking/plugins/commit/219eb9e0464761c47383d239aba206da695e1a43
 CVE-2020-10748
 	RESERVED
-CVE-2020-10747 [local account takeover/HBAC rules bypass]
-	RESERVED
-	- freeipa <unfixed>
-	NOTE: https://pagure.io/freeipa/issue/8326
-	NOTE: https://pagure.io/freeipa/c/4911a3f05514a7c0ac66e4ef5004581cced8519f (master)
-	NOTE: https://pagure.io/freeipa/c/930f4b3d1dc03f9e365b007b027d65e146a08f05 (ipa-4-8)
-	NOTE: https://pagure.io/freeipa/c/62400d6d240c1bb68987a1ff194ee7cd6c6d3cf0 (ipa-4-6)
-	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1810160
+CVE-2020-10747
+	REJECTED
 CVE-2020-10746
 	RESERVED
 CVE-2020-10745



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18cc2ddae66b7d42540f582affa064bd6a97bd0e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18cc2ddae66b7d42540f582affa064bd6a97bd0e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200617/8520b30d/attachment.html>


More information about the debian-security-tracker-commits mailing list