[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso carnil at debian.org
Sat May 2 21:10:36 BST 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
949b9f6a by security tracker role at 2020-05-02T20:10:28+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -862,7 +862,7 @@ CVE-2020-12245 (Grafana before 6.7.3 allows table-panel XSS via column.title or
 CVE-2020-12244
 	RESERVED
 CVE-2020-12243 (In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters wi ...)
-	{DSA-4666-1}
+	{DSA-4666-1 DLA-2199-1}
 	- openldap 2.4.50+dfsg-1
 	NOTE: https://bugs.openldap.org/show_bug.cgi?id=9202
 	NOTE: https://git.openldap.org/openldap/openldap/-/commit/d38d48fc8f572dedfb67b9da61a2ba3b125ced91 (master)
@@ -11695,8 +11695,8 @@ CVE-2020-8159
 	RESERVED
 CVE-2020-8158
 	RESERVED
-CVE-2020-8157
-	RESERVED
+CVE-2020-8157 (UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Ke ...)
+	TODO: check
 CVE-2020-8156
 	RESERVED
 CVE-2020-8155
@@ -12944,8 +12944,8 @@ CVE-2020-7647
 	RESERVED
 CVE-2020-7646
 	RESERVED
-CVE-2020-7645
-	RESERVED
+CVE-2020-7645 (All versions of chrome-launcher allow execution of arbitrary commands, ...)
+	TODO: check
 CVE-2020-7644 (fun-map through 3.3.1 is vulnerable to Prototype Pollution. The functi ...)
 	TODO: check
 CVE-2020-7643 (paypal-adaptive through 0.4.2 manipulation of JavaScript objects resul ...)
@@ -17445,8 +17445,8 @@ CVE-2020-5729 (In OpenMRS 2.9 and prior, the UI Framework Error Page reflects ar
 	NOT-FOR-US: OpenMRS
 CVE-2020-5728 (OpenMRS 2.9 and prior copies "Referrer" header values into an html ele ...)
 	NOT-FOR-US: OpenMRS
-CVE-2020-5727
-	RESERVED
+CVE-2020-5727 (Authentication bypass using an alternate path or channel in SimpliSafe ...)
+	TODO: check
 CVE-2020-5726 (The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQ ...)
 	NOT-FOR-US: Grandstream
 CVE-2020-5725 (The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQ ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/949b9f6a7af3f1f0453af509f6f76bbed49c40ad

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/949b9f6a7af3f1f0453af509f6f76bbed49c40ad
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200502/a9616fbd/attachment.html>


More information about the debian-security-tracker-commits mailing list