[Git][security-tracker-team/security-tracker][master] Process some NFUs

Neil Williams (@codehelp) codehelp at debian.org
Wed Aug 3 11:25:22 BST 2022



Neil Williams pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9d9778ff by Neil Williams at 2022-08-03T11:25:07+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6882,7 +6882,7 @@ CVE-2022-34627
 CVE-2022-34626
 	RESERVED
 CVE-2022-34625 (Mealie1.0.0beta3 was discovered to contain a Server-Side Template Inje ...)
-	TODO: check
+	NOT-FOR-US: hay-kot/mealie
 CVE-2022-34624
 	RESERVED
 CVE-2022-34623
@@ -6894,9 +6894,9 @@ CVE-2022-34621
 CVE-2022-34620
 	RESERVED
 CVE-2022-34619 (A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 all ...)
-	TODO: check
+	NOT-FOR-US: hay-kot/mealie
 CVE-2022-34618 (A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 ...)
-	TODO: check
+	NOT-FOR-US: hay-kot/mealie
 CVE-2022-34617
 	RESERVED
 CVE-2022-34616
@@ -6906,7 +6906,7 @@ CVE-2022-34615
 CVE-2022-34614
 	RESERVED
 CVE-2022-34613 (Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability whic ...)
-	TODO: check
+	NOT-FOR-US: hay-kot/mealie
 CVE-2022-34612 (Rizin v0.4.0 and below was discovered to contain an integer overflow v ...)
 	NOT-FOR-US: Rizin
 CVE-2022-34611 (A cross-site scripting (XSS) vulnerability in /index.php/?p=report of  ...)
@@ -20236,7 +20236,7 @@ CVE-2022-1470 (The Ultimate WooCommerce CSV Importer WordPress plugin through 2.
 CVE-2022-1469 (The FiboSearch WordPress plugin before 1.17.0 does not sanitise and es ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-29808 (In Quest KACE Systems Management Appliance (SMA) through 12.0, predict ...)
-	TODO: check
+	NOT-FOR-US: Quest KACE System Management Appliance
 CVE-2022-29807 (A SQL injection vulnerability exists within Quest KACE Systems Managem ...)
 	NOT-FOR-US: Quest KACE System Management Appliance
 CVE-2022-29806 (ZoneMinder before 1.36.13 allows remote code execution via an invalid  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9d9778ff9b3752ff0a5ac4f82e7cf81591c4a6fb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9d9778ff9b3752ff0a5ac4f82e7cf81591c4a6fb
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220803/44c60dec/attachment.htm>


More information about the debian-security-tracker-commits mailing list