[Git][security-tracker-team/security-tracker][master] Process some NFUs

Neil Williams (@codehelp) codehelp at debian.org
Tue Jul 5 10:36:38 BST 2022



Neil Williams pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5bc11825 by Neil Williams at 2022-07-05T10:36:14+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -10625,13 +10625,13 @@ CVE-2022-31115 (opensearch-ruby is a community-driven, open source fork of elast
 CVE-2022-31114
 	RESERVED
 CVE-2022-31113 (Canarytokens is an open source tool which helps track activity and act ...)
-	TODO: check
+	NOT-FOR-US: thinkst/canarytokens
 CVE-2022-31112 (Parse Server is an open source backend that can be deployed to any inf ...)
-	TODO: check
+	NOT-FOR-US: Node parse-server
 CVE-2022-31111
 	RESERVED
 CVE-2022-31110 (RSSHub is an open source, extensible RSS feed generator. In commits pr ...)
-	TODO: check
+	NOT-FOR-US: RSSHub
 CVE-2022-31109
 	RESERVED
 CVE-2022-31108 (Mermaid is a JavaScript based diagramming and charting tool that uses  ...)
@@ -10648,15 +10648,15 @@ CVE-2022-31105
 CVE-2022-31104 (Wasmtime is a standalone runtime for WebAssembly. In affected versions ...)
 	NOT-FOR-US: wasmtime
 CVE-2022-31103 (lettersanitizer is a DOM-based HTML email sanitizer for in-browser ema ...)
-	TODO: check
+	NOT-FOR-US: Node lettersanitizer
 CVE-2022-31102
 	RESERVED
 CVE-2022-31101 (prestashop/blockwishlist is a prestashop extension which adds a block  ...)
 	NOT-FOR-US: prestashop extension
 CVE-2022-31100 (rulex is a new, portable, regular expression language. When parsing un ...)
-	TODO: check
+	NOT-FOR-US: rulex-rs/pomsky
 CVE-2022-31099 (rulex is a new, portable, regular expression language. When parsing un ...)
-	TODO: check
+	NOT-FOR-US: rulex-rs/pomsky
 CVE-2022-31098 (Weave GitOps is a simple open source developer platform for people who ...)
 	NOT-FOR-US: Weave GitOps
 CVE-2022-31097
@@ -10686,7 +10686,7 @@ CVE-2022-31090 (Guzzle, an extensible PHP HTTP client. `Authorization` headers o
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-25mq-v84q-4j7r
 	NOTE: https://github.com/guzzle/guzzle/commit/1dd98b0564cb3f6bd16ce683cb755f94c10fbd82 (7.4.5)
 CVE-2022-31089 (Parse Server is an open source backend that can be deployed to any inf ...)
-	TODO: check
+	NOT-FOR-US: Node parse-server
 CVE-2022-31088 (LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. ...)
 	- ldap-account-manager 8.0.1-1
 	NOTE: https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-wxf8-9x99-6gp4



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5bc118256b303f338eb6cef64aa9326a51a040d8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5bc118256b303f338eb6cef64aa9326a51a040d8
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220705/5765a6e4/attachment.htm>


More information about the debian-security-tracker-commits mailing list