[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Apr 6 09:10:34 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a50733c5 by security tracker role at 2023-04-06T08:10:20+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,69 @@
+CVE-2023-29421 (An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is  ...)
+	TODO: check
+CVE-2023-29420 (An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is  ...)
+	TODO: check
+CVE-2023-29419 (An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is  ...)
+	TODO: check
+CVE-2023-29418 (An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is  ...)
+	TODO: check
+CVE-2023-29417 (** DISPUTED ** An issue was discovered in libbzip3.a in bzip3 1.2.2. T ...)
+	TODO: check
+CVE-2023-29416 (An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A bz3_dec ...)
+	TODO: check
+CVE-2023-29415 (An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial  ...)
+	TODO: check
+CVE-2023-29414
+	RESERVED
+CVE-2023-29413
+	RESERVED
+CVE-2023-29412
+	RESERVED
+CVE-2023-29411
+	RESERVED
+CVE-2023-29410
+	RESERVED
+CVE-2023-29409
+	RESERVED
+CVE-2023-29408
+	RESERVED
+CVE-2023-29407
+	RESERVED
+CVE-2023-29406
+	RESERVED
+CVE-2023-29405
+	RESERVED
+CVE-2023-29404
+	RESERVED
+CVE-2023-29403
+	RESERVED
+CVE-2023-29402
+	RESERVED
+CVE-2023-29401
+	RESERVED
+CVE-2023-29400
+	RESERVED
+CVE-2023-1904
+	RESERVED
+CVE-2023-1903
+	RESERVED
+CVE-2023-1902
+	RESERVED
+CVE-2023-1901
+	RESERVED
+CVE-2023-1900
+	RESERVED
+CVE-2023-1899
+	RESERVED
+CVE-2023-1898
+	RESERVED
+CVE-2023-1897
+	RESERVED
+CVE-2023-1896
+	RESERVED
+CVE-2023-1895
+	RESERVED
+CVE-2023-1894
+	RESERVED
 CVE-2023-29399
 	RESERVED
 CVE-2023-29398
@@ -351,8 +417,7 @@ CVE-2023-1857 (A vulnerability was found in SourceCodester Online Computer and L
 	NOT-FOR-US: SourceCodester Online Computer and Laptop Store
 CVE-2023-1856 (A vulnerability has been found in SourceCodester Air Cargo Management  ...)
 	NOT-FOR-US: SourceCodester Air Cargo Management System
-CVE-2023-1855 [hwmon: (xgene) Fix use after free bug in xgene_hwmon_remove due to race condition]
-	RESERVED
+CVE-2023-1855 (A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon ...)
 	- linux <unfixed>
 	NOTE: https://git.kernel.org/linus/cb090e64cf25602b9adaf32d5dfc9c8bec493cd1 (6.3-rc3)
 CVE-2023-1854 (A vulnerability, which was classified as problematic, was found in Sou ...)
@@ -734,8 +799,8 @@ CVE-2023-1789 (Improper Input Validation in GitHub repository firefly-iii/firefl
 	NOT-FOR-US: firefly-iii
 CVE-2023-1788 (Insufficient Session Expiration in GitHub repository firefly-iii/firef ...)
 	TODO: check
-CVE-2023-1787
-	RESERVED
+CVE-2023-1787 (An issue has been discovered in GitLab affecting all versions starting ...)
+	TODO: check
 CVE-2023-1786
 	RESERVED
 CVE-2023-1785 (A vulnerability was found in SourceCodester Earnings and Expense Track ...)
@@ -870,8 +935,8 @@ CVE-2023-29093
 	RESERVED
 CVE-2023-1783
 	RESERVED
-CVE-2023-1782
-	RESERVED
+CVE-2023-1782 (HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow  ...)
+	TODO: check
 CVE-2023-1781
 	RESERVED
 CVE-2023-1780
@@ -1088,8 +1153,8 @@ CVE-2023-1735 (A vulnerability classified as critical was found in SourceCodeste
 	NOT-FOR-US: SourceCodester Young Entrepreneur E-Negosyo System
 CVE-2023-1734 (A vulnerability classified as critical has been found in SourceCodeste ...)
 	NOT-FOR-US: SourceCodester Young Entrepreneur E-Negosyo System
-CVE-2023-1733
-	RESERVED
+CVE-2023-1733 (A denial of service condition exists in the Prometheus server bundled  ...)
+	TODO: check
 CVE-2023-1732
 	RESERVED
 CVE-2023-1731
@@ -1156,8 +1221,8 @@ CVE-2023-29023
 	RESERVED
 CVE-2023-29022
 	RESERVED
-CVE-2023-1710
-	RESERVED
+CVE-2023-1710 (A sensitive information disclosure vulnerability in GitLab affecting a ...)
+	TODO: check
 CVE-2023-1709
 	RESERVED
 CVE-2023-29021
@@ -1295,8 +1360,8 @@ CVE-2023-28960
 	RESERVED
 CVE-2023-28959
 	RESERVED
-CVE-2023-1708
-	RESERVED
+CVE-2023-1708 (An issue was identified in GitLab CE/EE affecting all versions from 1. ...)
+	TODO: check
 CVE-2023-1707
 	RESERVED
 CVE-2023-1706
@@ -1596,7 +1661,8 @@ CVE-2023-1650
 	RESERVED
 CVE-2023-1649
 	RESERVED
-CVE-2023-1648 (An issue has been discovered in GitLab DAST API scanner affecting all  ...)
+CVE-2023-1648
+	REJECTED
 	NOT-FOR-US: GitLab DAST API scanner
 CVE-2022-48429 (In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 refle ...)
 	NOT-FOR-US: JetBrains Hub
@@ -1633,7 +1699,7 @@ CVE-2023-28881
 CVE-2023-28880
 	RESERVED
 CVE-2023-28879 (In Artifex Ghostscript through 10.01.0, there is a buffer overflow lea ...)
-	{DLA-3381-1}
+	{DSA-5383-1 DLA-3381-1}
 	- ghostscript 10.0.0~dfsg-11 (bug #1033757)
 	NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=706494 (not public)
 	NOTE: Fixed by: https://git.ghostscript.com/?p=ghostpdl.git;h=37ed5022cecd584de868933b5b60da2e995b3179
@@ -2114,8 +2180,7 @@ CVE-2023-1583 (A NULL pointer dereference was found in io_file_bitmap_get in io_
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	[buster] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/axboe/linux-block.git/commit/?h=io_uring-6.3&id=761efd55a0227aca3a69deacdaa112fffd44fe37
-CVE-2023-1582
-	RESERVED
+CVE-2023-1582 (A race problem was found in fs/proc/task_mmu.c in the memory managemen ...)
 	- linux 5.15.15-1
 	[bullseye] - linux 5.10.103-1
 	NOTE: https://git.kernel.org/linus/24d7275ce2791829953ed4e72f68277ceb2571c6 (5.17-rc4)
@@ -3321,8 +3386,8 @@ CVE-2023-1419
 	RESERVED
 CVE-2023-1418 (A vulnerability classified as problematic was found in SourceCodester  ...)
 	NOT-FOR-US: SourceCodester Friendly Island Pizza Website and Ordering System
-CVE-2023-1417
-	RESERVED
+CVE-2023-1417 (An issue has been discovered in GitLab affecting all versions starting ...)
+	TODO: check
 CVE-2023-1416 (A vulnerability classified as critical has been found in Simple Art Ga ...)
 	NOT-FOR-US: Simple Art Gallery
 CVE-2023-1415 (A vulnerability was found in Simple Art Gallery 1.0. It has been decla ...)
@@ -4436,8 +4501,8 @@ CVE-2023-28048
 	RESERVED
 CVE-2023-28047
 	RESERVED
-CVE-2023-28046
-	RESERVED
+CVE-2023-28046 (Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary  ...)
+	TODO: check
 CVE-2023-28045
 	RESERVED
 CVE-2023-28044
@@ -5960,8 +6025,8 @@ CVE-2015-10089 (A vulnerability classified as problematic has been found in flam
 	NOT-FOR-US: flame.js
 CVE-2023-1168 (An authenticated remote code execution vulnerability exists in the AOS ...)
 	NOT-FOR-US: HPE
-CVE-2023-1167
-	RESERVED
+CVE-2023-1167 (Improper authorization in Gitlab EE affecting all versions from 12.3.0 ...)
+	TODO: check
 CVE-2023-1166
 	RESERVED
 CVE-2022-4929 (A vulnerability was found in icplayer up to 0.818. It has been rated a ...)
@@ -6703,8 +6768,8 @@ CVE-2023-23554 (Uncontrolled search path element vulnerability exists in pg_ivm
 	NOT-FOR-US: pg_ivm
 CVE-2023-22847 (Information disclosure vulnerability exists in pg_ivm versions prior t ...)
 	NOT-FOR-US: pg_ivm
-CVE-2023-1098
-	RESERVED
+CVE-2023-1098 (An information disclosure vulnerability has been discovered in GitLab  ...)
+	TODO: check
 CVE-2023-1097 (Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vu ...)
 	NOT-FOR-US: Baicells EG7035-M11 devices
 CVE-2023-1096
@@ -6863,8 +6928,8 @@ CVE-2023-1073 (A memory corruption flaw was found in the Linux kernel’s hu
 	NOTE: https://www.openwall.com/lists/oss-security/2023/01/17/3
 CVE-2023-1072 (An issue has been discovered in GitLab affecting all versions starting ...)
 	- gitlab <unfixed>
-CVE-2023-1071
-	RESERVED
+CVE-2023-1071 (An issue has been discovered in GitLab affecting all versions from 15. ...)
+	TODO: check
 CVE-2023-1070 (External Control of File Name or Path in GitHub repository nilsteampas ...)
 	- teampass <itp> (bug #730180)
 CVE-2023-1069 (The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPre ...)
@@ -9113,8 +9178,8 @@ CVE-2023-0969
 	RESERVED
 CVE-2023-0968 (The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Si ...)
 	NOT-FOR-US: Watu Quiz plugin for WordPress
-CVE-2023-0967
-	RESERVED
+CVE-2023-0967 (Bhima version 1.27.0 allows an attacker authenticated with normal user ...)
+	TODO: check
 CVE-2023-0966 (A vulnerability classified as problematic was found in SourceCodester  ...)
 	NOT-FOR-US: SourceCodester Online Eyewear Shop
 CVE-2023-0965
@@ -9129,8 +9194,8 @@ CVE-2023-0961 (A vulnerability was found in SourceCodester Music Gallery Site 1.
 	NOT-FOR-US: SourceCodester Music Gallery Site
 CVE-2023-0960 (A vulnerability was found in SeaCMS 11.6 and classified as problematic ...)
 	NOT-FOR-US: SeaCMS
-CVE-2023-0959
-	RESERVED
+CVE-2023-0959 (Bhima version 1.27.0 allows a remote attacker to update the privileges ...)
+	TODO: check
 CVE-2023-0958
 	RESERVED
 CVE-2023-0957 (An issue was discovered in Gitpod versions prior to release-2022.11.2. ...)
@@ -9209,8 +9274,8 @@ CVE-2023-0946 (A vulnerability has been found in SourceCodester Best POS Managem
 	NOT-FOR-US: SourceCodester Best POS Management System
 CVE-2023-0945 (A vulnerability, which was classified as problematic, was found in Sou ...)
 	NOT-FOR-US: SourceCodester Best POS Management System
-CVE-2023-0944
-	RESERVED
+CVE-2023-0944 (Bhima version 1.27.0 allows an authenticated attacker with regular use ...)
+	TODO: check
 CVE-2023-0943 (A vulnerability, which was classified as problematic, has been found i ...)
 	NOT-FOR-US: SourceCodester Best POS Management System
 CVE-2023-0942 (The Japanized For WooCommerce plugin for WordPress is vulnerable to Re ...)
@@ -10617,16 +10682,16 @@ CVE-2023-0844 (The Namaste! LMS WordPress plugin before 2.6 does not sanitize an
 	NOT-FOR-US: WordPress plugin
 CVE-2023-0843
 	RESERVED
-CVE-2023-0842
-	RESERVED
+CVE-2023-0842 (xml2js version 0.4.23 allows an external attacker to edit or add new p ...)
+	TODO: check
 CVE-2023-0841 (A vulnerability, which was classified as critical, has been found in G ...)
 	- gpac <undetermined>
 CVE-2023-0840 (A vulnerability classified as problematic was found in PHPCrazy 1.1.1. ...)
 	NOT-FOR-US: PHPCrazy
 CVE-2023-0839 (Improper Protection for Outbound Error Messages and Alert Signals vuln ...)
 	NOT-FOR-US: ProMIS Process Co. InSCADA
-CVE-2023-0838
-	RESERVED
+CVE-2023-0838 (An issue has been discovered in GitLab affecting versions starting fro ...)
+	TODO: check
 CVE-2023-0837
 	RESERVED
 CVE-2023-25780
@@ -11619,8 +11684,8 @@ CVE-2023-25544 (Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat'
 	NOT-FOR-US: Dell
 CVE-2023-25543
 	RESERVED
-CVE-2023-25542
-	RESERVED
+CVE-2023-25542 (Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an impr ...)
+	TODO: check
 CVE-2023-25541
 	RESERVED
 CVE-2023-25540 (Dell PowerScale OneFS 9.4.0.x contains an incorrect default permission ...)
@@ -13725,8 +13790,8 @@ CVE-2023-24749
 	RESERVED
 CVE-2023-24748
 	RESERVED
-CVE-2023-24747
-	RESERVED
+CVE-2023-24747 (Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) ...)
+	TODO: check
 CVE-2023-24746
 	RESERVED
 CVE-2023-24745
@@ -13771,7 +13836,7 @@ CVE-2023-24726 (Art Gallery Management System v1.0 was discovered to contain a S
 	NOT-FOR-US: Art Gallery Management System
 CVE-2023-24725
 	RESERVED
-CVE-2023-24724 (** DISPUTED ** A stored cross site scripting (XSS) vulnerability was d ...)
+CVE-2023-24724 (A stored cross site scripting (XSS) vulnerability was discovered in th ...)
 	TODO: check
 CVE-2023-24723
 	RESERVED
@@ -13779,8 +13844,8 @@ CVE-2023-24722
 	RESERVED
 CVE-2023-24721
 	RESERVED
-CVE-2023-24720
-	RESERVED
+CVE-2023-24720 (An arbitrary file upload vulnerability in readium-js v0.32.0 allows at ...)
+	TODO: check
 CVE-2023-24719
 	RESERVED
 CVE-2023-24718
@@ -14252,8 +14317,8 @@ CVE-2023-0525
 	RESERVED
 CVE-2023-0524 (As part of our Security Development Lifecycle, a potential privilege e ...)
 	NOT-FOR-US: Tenable
-CVE-2023-0523
-	RESERVED
+CVE-2023-0523 (An issue has been discovered in GitLab affecting all versions starting ...)
+	TODO: check
 CVE-2023-0522
 	RESERVED
 CVE-2023-0521
@@ -14930,8 +14995,8 @@ CVE-2023-0452 (All versions of Econolite EOS traffic control software are vulner
 	NOT-FOR-US: Econolite EOS traffic control software
 CVE-2023-0451 (All versions of Econolite EOS traffic control software are vulnerable  ...)
 	NOT-FOR-US: Econolite EOS traffic control software
-CVE-2023-0450
-	RESERVED
+CVE-2023-0450 (An issue has been discovered in GitLab affecting all versions starting ...)
+	TODO: check
 CVE-2023-0449
 	REJECTED
 CVE-2023-0448 (The WP Helper Lite WordPress plugin, in versions < 4.3, returns all ...)
@@ -15814,8 +15879,8 @@ CVE-2023-23989
 	RESERVED
 CVE-2023-23988
 	RESERVED
-CVE-2023-23987
-	RESERVED
+CVE-2023-23987 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEv ...)
+	TODO: check
 CVE-2023-23986
 	RESERVED
 CVE-2023-23985
@@ -15824,14 +15889,14 @@ CVE-2023-23984 (Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company B
 	NOT-FOR-US: WordPress plugin
 CVE-2023-23983 (Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2023-23982
-	RESERVED
-CVE-2023-23981
-	RESERVED
+CVE-2023-23982 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPGe ...)
+	TODO: check
+CVE-2023-23981 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Quan ...)
+	TODO: check
 CVE-2023-23980
 	RESERVED
-CVE-2023-23979
-	RESERVED
+CVE-2023-23979 (Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Q ...)
+	TODO: check
 CVE-2023-23978
 	RESERVED
 CVE-2023-23977 (Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability i ...)
@@ -15844,10 +15909,10 @@ CVE-2023-23974 (Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Qui
 	NOT-FOR-US: WordPress plugin
 CVE-2023-23973 (Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Cont ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2023-23972
-	RESERVED
-CVE-2023-23971
-	RESERVED
+CVE-2023-23972 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smpl ...)
+	TODO: check
+CVE-2023-23971 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Code ...)
+	TODO: check
 CVE-2023-23970
 	RESERVED
 CVE-2023-23907
@@ -16320,8 +16385,8 @@ CVE-2023-23817
 	RESERVED
 CVE-2023-23816
 	RESERVED
-CVE-2023-23815
-	RESERVED
+CVE-2023-23815 (Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability i ...)
+	TODO: check
 CVE-2023-23814
 	RESERVED
 CVE-2023-23813
@@ -17068,8 +17133,8 @@ CVE-2023-0321 (Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3
 	NOT-FOR-US: Campbell
 CVE-2023-0320 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
 	NOT-FOR-US: UBYS
-CVE-2023-0319
-	RESERVED
+CVE-2023-0319 (An issue has been discovered in GitLab affecting all versions starting ...)
+	TODO: check
 CVE-2023-0318
 	RESERVED
 CVE-2023-0317
@@ -40961,8 +41026,8 @@ CVE-2022-3515 (A vulnerability was found in the Libksba library due to an intege
 	NOTE: https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582b
 CVE-2022-3514 (An issue has been discovered in GitLab CE/EE affecting all versions st ...)
 	- gitlab <unfixed>
-CVE-2022-3513
-	RESERVED
+CVE-2022-3513 (An issue has been discovered in GitLab affecting all versions starting ...)
+	TODO: check
 CVE-2022-3512 (Using warp-cli command "add-trusted-ssid", a user was able to disconne ...)
 	NOT-FOR-US: Cloudflare
 CVE-2022-3511 (The Awesome Support WordPress plugin before 6.1.2 does not ensure that ...)
@@ -43953,8 +44018,8 @@ CVE-2022-3377 (Horner Automation's Cscape version 9.90 SP 6 and prior does not p
 	NOT-FOR-US: Horner Automation's Cscape
 CVE-2022-3376 (Weak Password Requirements in GitHub repository ikus060/rdiffweb prior ...)
 	- rdiffweb <itp> (bug #969974)
-CVE-2022-3375
-	RESERVED
+CVE-2022-3375 (An issue has been discovered in GitLab affecting all versions starting ...)
+	TODO: check
 CVE-2022-3374 (The Ocean Extra WordPress plugin before 2.0.5 unserialises the content ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-3373 (Out of bounds write in V8 in Google Chrome prior to 106.0.5249.91 allo ...)
@@ -55956,7 +56021,7 @@ CVE-2022-37393 (Zimbra's sudo configuration permits the zimbra user to execute t
 CVE-2022-2634 (An attacker may be able to execute malicious actions due to the lack o ...)
 	NOT-FOR-US: Digi ConnectPort X2D
 CVE-2022-37392 (Improper Check for Unusual or Exceptional Conditions vulnerability in  ...)
-	{DSA-5311-1}
+	{DSA-5311-1 DLA-3385-1}
 	- trafficserver 9.1.4+ds-1
 	NOTE: https://lists.apache.org/thread/mrj2lg4s0hf027rk7gz8t7hbn9xpfg02
 	NOTE: https://github.com/apache/trafficserver/commit/3b9cbf873a77bb7f9297f2b16496a290e0cf7de1 (master)
@@ -68365,7 +68430,7 @@ CVE-2022-32751
 CVE-2022-32750 (IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0 ...)
 	NOT-FOR-US: IBM
 CVE-2022-32749 (Improper Check for Unusual or Exceptional Conditions vulnerability han ...)
-	{DSA-5311-1}
+	{DSA-5311-1 DLA-3385-1}
 	- trafficserver 9.1.4+ds-1
 	NOTE: https://lists.apache.org/thread/mrj2lg4s0hf027rk7gz8t7hbn9xpfg02
 	NOTE: https://github.com/apache/trafficserver/pull/9243
@@ -70744,12 +70809,12 @@ CVE-2022-31892
 	RESERVED
 CVE-2022-31891
 	RESERVED
-CVE-2022-31890
-	RESERVED
-CVE-2022-31889
-	RESERVED
-CVE-2022-31888
-	RESERVED
+CVE-2022-31890 (SQL Injection vulnerability in audit/class.audit.php in osTicket osTic ...)
+	TODO: check
+CVE-2022-31889 (Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs. ...)
+	TODO: check
+CVE-2022-31888 (Session Fixation vulnerability in in function login in class.auth.php  ...)
+	TODO: check
 CVE-2022-31887 (Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability ...)
 	NOT-FOR-US: Marval MSM
 CVE-2022-31886 (Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery  ...)
@@ -71087,11 +71152,11 @@ CVE-2022-31780 (Improper Input Validation vulnerability in HTTP/2 frame handling
 	- trafficserver 9.1.3+ds-1
 	NOTE: https://lists.apache.org/thread/rc64lwbdgrkv674koc3zl1sljr9vwg21
 CVE-2022-31779 (Improper Input Validation vulnerability in HTTP/2 header parsing of Ap ...)
-	{DSA-5206-1}
+	{DSA-5206-1 DLA-3385-1}
 	- trafficserver 9.1.3+ds-1
 	NOTE: https://lists.apache.org/thread/rc64lwbdgrkv674koc3zl1sljr9vwg21
 CVE-2022-31778 (Improper Input Validation vulnerability in handling the Transfer-Encod ...)
-	{DSA-5206-1}
+	{DSA-5206-1 DLA-3385-1}
 	- trafficserver 9.1.3+ds-1
 	NOTE: https://lists.apache.org/thread/rc64lwbdgrkv674koc3zl1sljr9vwg21
 CVE-2022-31777 (A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2. ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a50733c52bee22ea367b7b9bd987049a4215365c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a50733c52bee22ea367b7b9bd987049a4215365c
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230406/defc6c92/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list