[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Mar 4 08:17:01 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
99f66140 by Salvatore Bonaccorso at 2022-03-04T09:16:34+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3093,7 +3093,7 @@ CVE-2022-25222
 CVE-2022-25221
 	RESERVED
 CVE-2022-25220 (PeteReport Version 0.5 allows an authenticated admin user to inject pe ...)
-	TODO: check
+	NOT-FOR-US: PeteReport
 CVE-2022-25219
 	RESERVED
 CVE-2022-25218
@@ -10220,9 +10220,9 @@ CVE-2022-23054 (Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XS
 CVE-2022-23053 (Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via  ...)
 	NOT-FOR-US: Openmct
 CVE-2022-23052 (PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vu ...)
-	TODO: check
+	NOT-FOR-US: PeteReport
 CVE-2022-23051 (PeteReport Version 0.5 allows an authenticated admin user to inject pe ...)
-	TODO: check
+	NOT-FOR-US: PeteReport
 CVE-2022-23050
 	RESERVED
 CVE-2022-23049 (Exponent CMS 2.6.0patch2 allows an authenticated user to inject persis ...)
@@ -10466,7 +10466,7 @@ CVE-2022-22945 (VMware NSX Edge contains a CLI shell injection vulnerability. A
 CVE-2022-22944 (VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS ...)
 	NOT-FOR-US: VMware
 CVE-2022-22943 (VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains  ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2022-22942 [drm/vmwgfx: Fix stale file descriptors on failed usercopy]
 	RESERVED
 	- linux 5.15.15-2



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/99f66140da84b75426ccd6adc7f2898683d968c0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/99f66140da84b75426ccd6adc7f2898683d968c0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220304/588cd5cd/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list