[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 7 09:10:31 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fd447d3e by security tracker role at 2021-08-07T08:10:23+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,17 @@
+CVE-2021-38159
+	RESERVED
+CVE-2021-38158
+	RESERVED
+CVE-2021-38157 (** UNSUPPORTED WHEN ASSIGNED ** LeoStream Connection Broker 9.x before ...)
+	TODO: check
+CVE-2021-38156
+	RESERVED
+CVE-2021-38155 (OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1 ...)
+	TODO: check
 CVE-2021-XXXX [lynx leaks password to remote servers via SNI]
 	- lynx <unfixed> (bug #991971)
 	NOTE: https://lists.nongnu.org/archive/html/lynx-dev/2021-08/msg00002.html
-CVE-2021-38160 [virtio_console: Assure used length from device is limited]
+CVE-2021-38160 (In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, da ...)
 	- linux <unfixed>
 	NOTE: https://git.kernel.org/linus/d00d8da5869a2608e97cfede094dfc5e11462a46
 CVE-2021-38154
@@ -16,8 +26,8 @@ CVE-2021-38150
 	RESERVED
 CVE-2021-38149 (index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 a ...)
 	NOT-FOR-US: Chikitsa Patient Management System
-CVE-2021-38148
-	RESERVED
+CVE-2021-38148 (Obsidian before 0.12.12 does not require user confirmation for non-htt ...)
+	TODO: check
 CVE-2021-38147
 	RESERVED
 CVE-2021-38146
@@ -54192,10 +54202,10 @@ CVE-2020-28090
 	RESERVED
 CVE-2020-28089
 	RESERVED
-CVE-2020-28088
-	RESERVED
-CVE-2020-28087
-	RESERVED
+CVE-2020-28088 (An arbitrary file upload vulnerability in /jeecg-boot/sys/common/uploa ...)
+	TODO: check
+CVE-2020-28087 (A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of  ...)
+	TODO: check
 CVE-2020-28086 (pass through 1.7.3 has a possibility of using a password for an uninte ...)
 	- password-store <unfixed> (unimportant)
 	NOTE: https://lists.zx2c4.com/pipermail/password-store/2014-March/000498.html
@@ -70255,18 +70265,18 @@ CVE-2020-21360
 	RESERVED
 CVE-2020-21359
 	RESERVED
-CVE-2020-21358
-	RESERVED
-CVE-2020-21357
-	RESERVED
-CVE-2020-21356
-	RESERVED
+CVE-2020-21358 (A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attac ...)
+	TODO: check
+CVE-2020-21357 (A stored cross site scripting (XSS) vulnerability in /admin.php?mod=us ...)
+	TODO: check
+CVE-2020-21356 (An information disclosure vulnerability in upload.php of PopojiCMS 1.2 ...)
+	TODO: check
 CVE-2020-21355
 	RESERVED
 CVE-2020-21354
 	RESERVED
-CVE-2020-21353
-	RESERVED
+CVE-2020-21353 (A stored cross site scripting (XSS) vulnerability in /admin/snippets.p ...)
+	TODO: check
 CVE-2020-21352
 	RESERVED
 CVE-2020-21351



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd447d3ef2b31c738932d7fae20270d5ad1a5a1e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd447d3ef2b31c738932d7fae20270d5ad1a5a1e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210807/85b49910/attachment.htm>


More information about the debian-security-tracker-commits mailing list