[Git][security-tracker-team/security-tracker][master] Process NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Mar 14 09:23:01 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9cacd8ef by Salvatore Bonaccorso at 2022-03-14T10:22:48+01:00
Process NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -451,7 +451,7 @@ CVE-2022-26956
 CVE-2022-26955
 	RESERVED
 CVE-2022-0937 (Stored xss in showdoc through file upload in GitHub repository star7th ...)
-	TODO: check
+	NOT-FOR-US: ShowDoc
 CVE-2022-26954
 	RESERVED
 CVE-2022-26953
@@ -3195,7 +3195,7 @@ CVE-2022-24437
 CVE-2022-24434
 	RESERVED
 CVE-2022-24433 (The package simple-git before 3.3.0 are vulnerable to Command Injectio ...)
-	TODO: check
+	NOT-FOR-US: simple-git
 CVE-2022-24431
 	RESERVED
 CVE-2022-24430
@@ -6413,7 +6413,7 @@ CVE-2022-0549
 CVE-2022-0548
 	RESERVED
 CVE-2022-24696 (Mirametrix Glance before 5.1.1.42207 (released on 2018-08-30) allows a ...)
-	TODO: check
+	NOT-FOR-US: Mirametrix Glance
 CVE-2022-24695
 	RESERVED
 CVE-2022-24694 (In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before ...)
@@ -8145,7 +8145,7 @@ CVE-2022-24130 (xterm through Patch 370, when Sixel support is enabled, allows a
 CVE-2022-24129 (The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allow ...)
 	NOT-FOR-US: Shibboleth identity provider OIDC OP plugin
 CVE-2022-24128 (Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege esc ...)
-	TODO: check
+	NOT-FOR-US: Timescale TimescaleDB
 CVE-2022-24127
 	RESERVED
 CVE-2022-24126
@@ -9570,7 +9570,7 @@ CVE-2022-23852 (Expat (aka libexpat) before 2.4.4 has a signed integer overflow
 CVE-2022-23851
 	RESERVED
 CVE-2022-0341 (Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vd ...)
-	TODO: check
+	NOT-FOR-US: vditor
 CVE-2022-0340
 	RESERVED
 CVE-2021-4209



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9cacd8efe142a322c2da7b2bae4becac43129e2d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9cacd8efe142a322c2da7b2bae4becac43129e2d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220314/58fa1f86/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list