[Git][security-tracker-team/security-tracker][master] CVE-2022-31008/rabbitmq-server: references patches reducing the affected versions range

Sylvain Beucler (@beuc) beuc at debian.org
Mon Oct 31 21:26:07 GMT 2022



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0076ed8e by Sylvain Beucler at 2022-10-31T22:23:20+01:00
CVE-2022-31008/rabbitmq-server: references patches reducing the affected versions range
not triaging, letting LTS front-desk and/or security-team confirm that buster&bullseye shouldn't be affected

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -37187,6 +37187,9 @@ CVE-2022-31008 (RabbitMQ is a multi-protocol messaging and streaming broker. In
 	- rabbitmq-server 3.10.8-1
 	NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-v9gv-xp36-jgj8
 	NOTE: https://github.com/rabbitmq/rabbitmq-server/pull/4841
+	NOTE: obfuscation introduced in (built-in) Shovel plugin in: https://github.com/rabbitmq/rabbitmq-server/commit/6dbdc991c3111aa4ffa12a150b1402cf5c5e798e (v3.10.0-beta.2)
+	NOTE: obfuscation introduced in (built-in) Federation plugin in: https://github.com/rabbitmq/rabbitmq-server/commit/c1b5812cee6ac038737d62ca0b32cfd2db537653 (v3.8.10-rc.1)
+	NOTE: set_credentials_obfuscation_secret introduced in: https://github.com/rabbitmq/rabbitmq-server/commit/5ea51050452ea45874e89166090cb825c1277656 (v3.8.10)
 CVE-2022-31007 (eLabFTW is an electronic lab notebook manager for research teams. Prio ...)
 	NOT-FOR-US: eLabFTW
 CVE-2022-31006 (indy-node is the server portion of Hyperledger Indy, a distributed led ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0076ed8e08340af238232179fa66f74f779dfb40

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0076ed8e08340af238232179fa66f74f779dfb40
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221031/f2dba2f9/attachment.htm>


More information about the debian-security-tracker-commits mailing list