[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Jul 19 13:46:44 BST 2022



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3368bed7 by Moritz Muehlenhoff at 2022-07-19T14:46:20+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -375,7 +375,7 @@ CVE-2022-2452
 CVE-2022-2451
 	RESERVED
 CVE-2022-36126 (An issue was discovered in Inductive Automation Ignition before 7.9.20 ...)
-	TODO: check
+	NOT-FOR-US: Inductive Automation Ignition
 CVE-2022-2450
 	RESERVED
 CVE-2022-2449
@@ -837,19 +837,19 @@ CVE-2022-35908
 CVE-2022-35907
 	RESERVED
 CVE-2022-35906 (An issue was discovered in Bentley MicroStation before 10.17.0.x and B ...)
-	TODO: check
+	NOT-FOR-US: Bantley MicroStation
 CVE-2022-35905 (An issue was discovered in Bentley MicroStation before 10.17.0.x and B ...)
-	TODO: check
+	NOT-FOR-US: Bantley MicroStation
 CVE-2022-35904 (An issue was discovered in Bentley MicroStation before 10.17.0.x and B ...)
-	TODO: check
+	NOT-FOR-US: Bantley MicroStation
 CVE-2022-35903 (An issue was discovered in Bentley MicroStation before 10.17.0.x and B ...)
-	TODO: check
+	NOT-FOR-US: Bantley MicroStation
 CVE-2022-35902 (An issue was discovered in Bentley MicroStation before 10.17.0.x and B ...)
-	TODO: check
+	NOT-FOR-US: Bantley MicroStation
 CVE-2022-35901 (An issue was discovered in Bentley MicroStation before 10.17.0.x and B ...)
-	TODO: check
+	NOT-FOR-US: Bantley MicroStation
 CVE-2022-35900 (An issue was discovered in Bentley MicroStation before 10.17.0.x and B ...)
-	TODO: check
+	NOT-FOR-US: Bantley MicroStation
 CVE-2022-35899
 	RESERVED
 CVE-2022-35898
@@ -869,7 +869,7 @@ CVE-2022-35892
 CVE-2022-35891
 	RESERVED
 CVE-2022-35890 (An issue was discovered in Inductive Automation Ignition before 7.9.20 ...)
-	TODO: check
+	NOT-FOR-US: Inductive Automation Ignition
 CVE-2022-35889
 	RESERVED
 CVE-2022-35888
@@ -907,9 +907,9 @@ CVE-2022-2446
 CVE-2022-2445
 	RESERVED
 CVE-2022-2444 (The Visualizer: Tables and Charts Manager for WordPress plugin for Wor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2443 (The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2442
 	RESERVED
 CVE-2022-2441
@@ -921,11 +921,11 @@ CVE-2022-2439
 CVE-2022-2438
 	RESERVED
 CVE-2022-2437 (The Feed Them Social – for Twitter feed, Youtube and more plugin ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2436
 	RESERVED
 CVE-2022-2435 (The AnyMind Widget plugin for WordPress is vulnerable to Cross-Site Re ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2434
 	RESERVED
 CVE-2022-2433
@@ -2065,7 +2065,7 @@ CVE-2022-35406 (A URL disclosure issue was discovered in Burp Suite before 2022.
 CVE-2022-35405
 	RESERVED
 CVE-2022-35404 (ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 ...)
-	TODO: check
+	NOT-FOR-US: ManageEngine Password Manager Pro
 CVE-2022-35403 (Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP  ...)
 	NOT-FOR-US: Zoho ManageEngine
 CVE-2022-35402
@@ -3281,13 +3281,13 @@ CVE-2022-2286 (Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. ...
 	NOTE: https://huntr.dev/bounties/fe7681fb-2318-436b-8e65-daf66cd597d8/
 	NOTE: https://github.com/vim/vim/commit/f12129f1714f7d2301935bb21d896609bdac221c (v9.0.0020)
 CVE-2022-34902 (This vulnerability allows local attackers to escalate privileges on af ...)
-	TODO: check
+	NOT-FOR-US: Parallels
 CVE-2022-34901 (This vulnerability allows local attackers to escalate privileges on af ...)
-	TODO: check
+	NOT-FOR-US: Parallels
 CVE-2022-34900 (This vulnerability allows local attackers to escalate privileges on af ...)
-	TODO: check
+	NOT-FOR-US: Parallels
 CVE-2022-34899 (This vulnerability allows local attackers to escalate privileges on af ...)
-	TODO: check
+	NOT-FOR-US: Parallels
 CVE-2022-34898
 	RESERVED
 CVE-2022-34897
@@ -3330,13 +3330,13 @@ CVE-2021-4234 (OpenVPN Access Server 2.10 and prior versions are susceptible to
 CVE-2022-34893
 	RESERVED
 CVE-2022-34892 (This vulnerability allows local attackers to escalate privileges on af ...)
-	TODO: check
+	NOT-FOR-US: Parallels
 CVE-2022-34891 (This vulnerability allows local attackers to escalate privileges on af ...)
-	TODO: check
+	NOT-FOR-US: Parallels
 CVE-2022-34890 (This vulnerability allows local attackers to disclose sensitive inform ...)
-	TODO: check
+	NOT-FOR-US: Parallels
 CVE-2022-34889 (This vulnerability allows local attackers to escalate privileges on af ...)
-	TODO: check
+	NOT-FOR-US: Parallels
 CVE-2022-34888
 	RESERVED
 CVE-2022-34887
@@ -3370,11 +3370,11 @@ CVE-2022-34903 (GnuPG through 2.3.6, in unusual situations where an attacker pos
 	NOTE: https://www.openwall.com/lists/oss-security/2022/06/30/1
 	NOTE: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=34c649b3601383cd11dbc76221747ec16fd68e1b
 CVE-2022-34875 (This vulnerability allows remote attackers to disclose sensitive infor ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2022-34874 (This vulnerability allows remote attackers to disclose sensitive infor ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2022-34873 (This vulnerability allows remote attackers to disclose sensitive infor ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2022-34872
 	RESERVED
 CVE-2022-34871
@@ -3755,23 +3755,23 @@ CVE-2022-2236
 CVE-2022-2235 (Insufficient sanitization in GitLab EE's external issue tracker affect ...)
 	- gitlab <not-affected> (Specific to EE)
 CVE-2017-20138 (A vulnerability was found in Itech Auction Script 6.49. It has been cl ...)
-	TODO: check
+	NOT-FOR-US: Itech
 CVE-2017-20137 (A vulnerability was found in Itech B2B Script 4.28. It has been rated  ...)
-	TODO: check
+	NOT-FOR-US: Itech
 CVE-2017-20136 (A vulnerability classified as critical has been found in Itech Classif ...)
-	TODO: check
+	NOT-FOR-US: Itech
 CVE-2017-20135 (A vulnerability classified as critical was found in Itech Dating Scrip ...)
-	TODO: check
+	NOT-FOR-US: Itech
 CVE-2017-20134 (A vulnerability, which was classified as critical, has been found in I ...)
-	TODO: check
+	NOT-FOR-US: Itech
 CVE-2017-20133 (A vulnerability, which was classified as critical, was found in Itech  ...)
-	TODO: check
+	NOT-FOR-US: Itech
 CVE-2017-20132 (A vulnerability was found in Itech Multi Vendor Script 6.49 and classi ...)
-	TODO: check
+	NOT-FOR-US: Itech
 CVE-2017-20131 (A vulnerability was found in Itech News Portal 6.28. It has been class ...)
-	TODO: check
+	NOT-FOR-US: Itech
 CVE-2017-20130 (A vulnerability was found in Itech Real Estate Script 3.12. It has bee ...)
-	TODO: check
+	NOT-FOR-US: Itech
 CVE-2017-20129 (A vulnerability was found in LogoStore. It has been classified as crit ...)
 	NOT-FOR-US: LogoStore
 CVE-2017-20128 (A vulnerability has been found in KB Messages PHP Script 1.0 and class ...)
@@ -3969,11 +3969,11 @@ CVE-2022-34660
 CVE-2022-2225
 	RESERVED
 CVE-2022-2224 (The WordPress plugin Gallery for Social Photo is vulnerable to Cross-S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2223 (The WordPress plugin Image Slider is vulnerable to Cross-Site Request  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2222 (The Download Monitor WordPress plugin before 4.5.91 does not ensure th ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2221 (Information Exposure vulnerability in My Account Settings of Devolutio ...)
 	NOT-FOR-US: Devolutions Remote Desktop Manager
 CVE-2022-2220
@@ -4062,29 +4062,29 @@ CVE-2022-34645
 CVE-2022-34644
 	RESERVED
 CVE-2022-34643 (RISCV ISA Sim commit ac466a21df442c59962589ba296c702631e041b5 implemen ...)
-	TODO: check
+	NOT-FOR-US: RISCV ISA Sim
 CVE-2022-34642 (The component mcontrol.action in RISCV ISA Sim commit ac466a21df442c59 ...)
-	TODO: check
+	NOT-FOR-US: RISCV ISA Sim
 CVE-2022-34641 (CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom co ...)
-	TODO: check
+	NOT-FOR-US: CVA6
 CVE-2022-34640 (The *tval of ecall/ebreak in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf ...)
-	TODO: check
+	NOT-FOR-US: CVA6
 CVE-2022-34639 (CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a treats non-standa ...)
-	TODO: check
+	NOT-FOR-US: CVA6
 CVE-2022-34638
 	RESERVED
 CVE-2022-34637 (CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a implements an inc ...)
-	TODO: check
+	NOT-FOR-US: CVA6
 CVE-2022-34636 (CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom co ...)
-	TODO: check
+	NOT-FOR-US: CVA6
 CVE-2022-34635 (The mstatus.sd field in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a9 ...)
-	TODO: check
+	NOT-FOR-US: CVA6
 CVE-2022-34634 (CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted  ...)
-	TODO: check
+	NOT-FOR-US: CVA6
 CVE-2022-34633 (CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted  ...)
-	TODO: check
+	NOT-FOR-US: CVA6
 CVE-2022-34632 (Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discov ...)
-	TODO: check
+	NOT-FOR-US: Rocket-Chip
 CVE-2022-34631
 	RESERVED
 CVE-2022-34630
@@ -4583,7 +4583,7 @@ CVE-2022-2196
 CVE-2022-2195
 	RESERVED
 CVE-2022-2194 (The Accept Stripe Payments WordPress plugin before 2.0.64 does not san ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2019-25071 (A vulnerability was found in Apple iPhone up to 12.4.1. It has been de ...)
 	NOT-FOR-US: Apple iPhone
 CVE-2022-34463
@@ -4831,9 +4831,9 @@ CVE-2022-2189
 CVE-2022-2188
 	RESERVED
 CVE-2022-2187 (The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not esca ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2186 (The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2017-20097 (A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2017-20096 (A vulnerability classified as problematic has been found in WP-SpamFre ...)
@@ -5043,7 +5043,7 @@ CVE-2022-2175 (Buffer Over-read in GitHub repository vim/vim prior to 8.2. ...)
 CVE-2022-2174 (Cross-site Scripting (XSS) - Reflected in GitHub repository microweber ...)
 	NOT-FOR-US: microweber
 CVE-2022-2173 (The Advanced Database Cleaner WordPress plugin before 3.1.1 does not e ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2172
 	RESERVED
 CVE-2022-2171
@@ -5051,9 +5051,9 @@ CVE-2022-2171
 CVE-2022-2170
 	RESERVED
 CVE-2022-2169 (The Loading Page with Loading Screen WordPress plugin before 1.0.83 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2168 (The Download Manager WordPress plugin before 3.2.44 does not escape a  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2167
 	RESERVED
 CVE-2022-34270
@@ -5347,21 +5347,21 @@ CVE-2022-2153
 CVE-2022-2152
 	RESERVED
 CVE-2022-2151 (The Best Contact Management Software WordPress plugin through 3.7.3 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2150
 	RESERVED
 CVE-2022-2149 (The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2148 (The LinkedIn Company Updates WordPress plugin through 1.5.3 does not s ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2147 (Cloudflare Warp for Windows from version 2022.2.95.0 contained an unqu ...)
 	NOT-FOR-US: Cloudflare Warp for Windows
 CVE-2022-2146 (The Import CSV Files WordPress plugin through 1.0 does not sanitise an ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2145 (Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed cre ...)
 	NOT-FOR-US: Cloudflare WARP client for Windows
 CVE-2022-2144 (The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-34167 (IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-s ...)
 	NOT-FOR-US: IBM
 CVE-2022-34166 (IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scr ...)
@@ -5403,7 +5403,7 @@ CVE-2022-2135
 CVE-2022-2134 (Denial of Service in GitHub repository inventree/inventree prior to 0. ...)
 	NOT-FOR-US: inventree
 CVE-2022-2133 (The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't valida ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2132
 	RESERVED
 CVE-2022-2131
@@ -5983,7 +5983,7 @@ CVE-2022-2119 (OFFIS DCMTK's (All versions prior to 3.6.7) service class provide
 	[bullseye] - dcmtk <no-dsa> (Minor issue)
 	[buster] - dcmtk <no-dsa> (Minor issue)
 CVE-2022-2118 (The 404s WordPress plugin before 3.5.1 does not sanitise and escape it ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2014-125025 (A vulnerability classified as problematic has been found in FFmpeg 2.0 ...)
 	- ffmpeg <not-affected> (Fixed before re-introduction to Debian as src:ffmpeg)
 	NOTE: Fixed by: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=6e42ccb9dbc13836cd52cda594f819d17af9afa2 (n2.2-rc1)
@@ -6099,13 +6099,13 @@ CVE-2022-33918
 CVE-2022-33917
 	RESERVED
 CVE-2022-2117 (The GiveWP plugin for WordPress is vulnerable to Sensitive Information ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2116
 	RESERVED
 CVE-2022-2115
 	RESERVED
 CVE-2022-2114 (The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2113 (Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inv ...)
 	NOT-FOR-US: inventree
 CVE-2022-2112 (Improper Neutralization of Formula Elements in a CSV File in GitHub re ...)
@@ -6198,7 +6198,7 @@ CVE-2022-28715
 CVE-2022-25986
 	RESERVED
 CVE-2022-2108 (The plugin Wbcom Designs – BuddyPress Group Reviews for WordPres ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2107
 	RESERVED
 CVE-2022-2106 (Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficient ...)
@@ -6212,7 +6212,7 @@ CVE-2022-2103 (An attacker with weak credentials could access the TCP port via a
 CVE-2022-2102 (Controls limiting uploads to certain file extensions may be bypassed.  ...)
 	NOT-FOR-US: Secheron
 CVE-2022-2101 (The Download Manager plugin for WordPress is vulnerable to Stored Cros ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-33880
 	RESERVED
 CVE-2022-33879 (The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in  ...)
@@ -6241,9 +6241,9 @@ CVE-2022-33870
 CVE-2022-33869
 	RESERVED
 CVE-2022-2100 (The Page Generator WordPress plugin before 1.6.5 does not sanitise and ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2099 (The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2098 (Weak Password Requirements in GitHub repository kromitgmbh/titra prior ...)
 	NOT-FOR-US: Titra
 CVE-2020-36549 (A vulnerability classified as critical was found in GE Voluson S8. Aff ...)
@@ -6492,7 +6492,7 @@ CVE-2022-2092 (The WooCommerce PDF Invoices & Packing Slips WordPress plugin
 CVE-2022-2091 (The Cache Images WordPress plugin before 3.2.1 does not implement nonc ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-2090 (The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2089 (The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-33758
@@ -8225,7 +8225,7 @@ CVE-2022-2054 (Command Injection in GitHub repository nuitka/nuitka prior to 0.9
 	NOTE: https://huntr.dev/bounties/ea4a842c-c48c-4aae-a599-3305125c63a7/
 	NOTE: https://github.com/nuitka/nuitka/commit/09647745d7cbb6ff32f9fa948f19d5558b32bcad
 CVE-2022-32985 (libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.0 ...)
-	TODO: check
+	NOT-FOR-US: Nexans FTTO GigaSwitch
 CVE-2022-32984
 	RESERVED
 CVE-2022-32983 (Knot Resolver through 5.5.1 may allow DNS cache poisoning when there i ...)
@@ -8777,7 +8777,7 @@ CVE-2022-28703
 CVE-2022-27498
 	RESERVED
 CVE-2022-2039 (The Free Live Chat Support plugin for WordPress is vulnerable to Cross ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-2038
 	RESERVED
 CVE-2022-2037 (Excessive Attack Surface in GitHub repository tooljet/tooljet prior to ...)
@@ -9175,7 +9175,7 @@ CVE-2022-2032
 CVE-2022-2031
 	RESERVED
 CVE-2022-2030 (A directory traversal vulnerability caused by specific character seque ...)
-	TODO: check
+	NOT-FOR-US: Zyxel
 CVE-2022-2029 (Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra ...)
 	NOT-FOR-US: kromitgmbh/titra
 CVE-2022-2028 (Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/t ...)
@@ -9388,7 +9388,7 @@ CVE-2022-2003
 CVE-2022-2002
 	RESERVED
 CVE-2022-2001 (The DX Share Selection plugin for WordPress is vulnerable to Cross-Sit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2022-32498
 	RESERVED
 CVE-2022-32497
@@ -9523,7 +9523,7 @@ CVE-2022-32452
 CVE-2022-32451
 	RESERVED
 CVE-2022-32450 (AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symb ...)
-	TODO: check
+	NOT-FOR-US: AnyDesk
 CVE-2022-32449 (TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command inj ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2022-32448
@@ -9555,7 +9555,7 @@ CVE-2022-32436
 CVE-2022-32435
 	RESERVED
 CVE-2022-32434 (EIPStackGroup OpENer v2.3.0 was discovered to contain a stack overflow ...)
-	TODO: check
+	NOT-FOR-US: EIPStackGroup OpENer
 CVE-2022-32433 (itsourcecode Advanced School Management System v1.0 is vulnerable to A ...)
 	NOT-FOR-US: itsourcecode Advanced School Management System
 CVE-2022-32432
@@ -9649,7 +9649,7 @@ CVE-2022-32389 (Isode SWIFT v4.0.2 was discovered to contain hard-coded credenti
 CVE-2022-32388
 	RESERVED
 CVE-2022-32387 (In Kentico before 13.0.66, attackers can achieve Denial of Service via ...)
-	TODO: check
+	NOT-FOR-US: Kentico
 CVE-2022-32386 (Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow vi ...)
 	NOT-FOR-US: Tenda
 CVE-2022-32385 (Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allo ...)
@@ -9785,7 +9785,7 @@ CVE-2022-32322
 CVE-2022-32321
 	RESERVED
 CVE-2022-32320 (A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium ...)
-	TODO: check
+	NOT-FOR-US: Ferdi
 CVE-2022-32319
 	RESERVED
 CVE-2022-32318 (Fast Food Ordering System v1.0 was discovered to contain a persistent  ...)
@@ -10022,7 +10022,7 @@ CVE-2022-1989
 CVE-2022-1988 (Cross-site Scripting (XSS) - Generic in GitHub repository neorazorx/fa ...)
 	NOT-FOR-US: neorazorx/facturascripts
 CVE-2022-32274 (The Transition Scheduler add-on 6.5.0 for Atlassian Jira is prone to s ...)
-	TODO: check
+	NOT-FOR-US: JIRA addon
 CVE-2022-32273 (As a result of an observable discrepancy in returned messages, OPSWAT  ...)
 	NOT-FOR-US: OPSWAT MetaDefender Core
 CVE-2022-32272 (OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3368bed74d41bc1b45abb907e1c94a146a3d41df

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3368bed74d41bc1b45abb907e1c94a146a3d41df
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220719/455c2e85/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list