[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 15 09:10:32 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7518bbbe by security tracker role at 2021-09-15T08:10:20+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,7 @@
+CVE-2021-41078
+	RESERVED
+CVE-2021-3801
+	RESERVED
 CVE-2021-41077 (The activation process in Travis CI, for certain 2021-09-03 through 20 ...)
 	TODO: check
 CVE-2021-41076
@@ -1693,8 +1697,8 @@ CVE-2021-40330 (git_connect_git in connect.c in Git before 2.30.1 allows a repos
 	NOTE: https://github.com/git/git/commit/a02ea577174ab8ed18f847cf1693f213e0b9c473
 CVE-2021-40329
 	RESERVED
-CVE-2021-3751
-	RESERVED
+CVE-2021-3751 (libmobi is vulnerable to Out-of-bounds Write ...)
+	TODO: check
 CVE-2021-40328
 	RESERVED
 CVE-2021-40327
@@ -5406,8 +5410,8 @@ CVE-2021-38675
 	RESERVED
 CVE-2021-38674
 	RESERVED
-CVE-2021-3706
-	RESERVED
+CVE-2021-3706 (adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag ...)
+	TODO: check
 CVE-2021-38673
 	RESERVED
 CVE-2021-38672
@@ -43136,18 +43140,18 @@ CVE-2021-23032 (On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x be
 	NOT-FOR-US: F5 BIG-IP
 CVE-2021-23031 (On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before ...)
 	NOT-FOR-US: F5 BIG-IP
-CVE-2021-23030
-	RESERVED
-CVE-2021-23029
-	RESERVED
-CVE-2021-23028
-	RESERVED
-CVE-2021-23027
-	RESERVED
-CVE-2021-23026
-	RESERVED
-CVE-2021-23025
-	RESERVED
+CVE-2021-23030 (On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2,  ...)
+	TODO: check
+CVE-2021-23029 (On version 16.0.x before 16.0.1.2, insufficient permission checks may  ...)
+	TODO: check
+CVE-2021-23028 (On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x befo ...)
+	TODO: check
+CVE-2021-23027 (On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x  ...)
+	TODO: check
+CVE-2021-23026 (BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x be ...)
+	TODO: check
+CVE-2021-23025 (On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x befo ...)
+	TODO: check
 CVE-2021-23024 (On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG ...)
 	NOT-FOR-US: F5
 CVE-2021-23023 (On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7518bbbe32721e4bcbd3b261db6aaa0c3502d46d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7518bbbe32721e4bcbd3b261db6aaa0c3502d46d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210915/4a6ca38e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list