[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Dec 15 08:46:15 GMT 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3d7007f2 by Salvatore Bonaccorso at 2021-12-15T09:45:54+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -304,7 +304,7 @@ CVE-2021-4110 (mruby is vulnerable to NULL Pointer Dereference ...)
 CVE-2021-4109
 	RESERVED
 CVE-2021-4108 (snipe-it is vulnerable to Improper Neutralization of Input During Web  ...)
-	TODO: check
+	NOT-FOR-US: snipe-it
 CVE-2022-0010
 	RESERVED
 CVE-2021-45040
@@ -492,7 +492,7 @@ CVE-2021-44950
 CVE-2021-44949 (glFusion CMS 1.7.9 is affected by an access control vulnerability via  ...)
 	NOT-FOR-US: glFusion CMS
 CVE-2021-44948 (glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF)  ...)
-	TODO: check
+	NOT-FOR-US: glFusion CMS
 CVE-2021-44947
 	RESERVED
 CVE-2021-44946
@@ -504,7 +504,7 @@ CVE-2021-44944
 CVE-2021-44943
 	RESERVED
 CVE-2021-44942 (glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF)  ...)
-	TODO: check
+	NOT-FOR-US: glFusion CMS
 CVE-2021-44941
 	RESERVED
 CVE-2021-44940
@@ -3015,11 +3015,11 @@ CVE-2021-44045 (An out-of-bounds write vulnerability exists when reading a DGN f
 CVE-2021-44044 (An out-of-bounds write vulnerability exists when reading a JPG file us ...)
 	NOT-FOR-US: Open Design Alliance Drawings SDK
 CVE-2021-44043 (An issue was discovered in UiPath App Studio 21.4.4. There is a persis ...)
-	TODO: check
+	NOT-FOR-US: UiPath
 CVE-2021-44042 (An issue was discovered in UiPath Assistant 21.4.4. User-controlled da ...)
-	TODO: check
+	NOT-FOR-US: UiPath
 CVE-2021-44041 (UiPath Assistant 21.4.4 will load and execute attacker controlled data ...)
-	TODO: check
+	NOT-FOR-US: UiPath
 CVE-2021-3985 (kimai2 is vulnerable to Improper Neutralization of Input During Web Pa ...)
 	NOT-FOR-US: kimai2
 CVE-2021-3984 (vim is vulnerable to Heap-based Buffer Overflow ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d7007f2bd32fcd4606a2b7e63bac9a822834006

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d7007f2bd32fcd4606a2b7e63bac9a822834006
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211215/605b3db3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list