[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Apr 16 09:11:15 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7a05456b by security tracker role at 2023-04-16T08:10:16+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,13 @@
+CVE-2023-30773
+	RESERVED
+CVE-2023-30771
+	RESERVED
+CVE-2015-10103
+	RESERVED
+CVE-2015-10102
+	RESERVED
+CVE-2015-10101 (A vulnerability classified as problematic was found in Google Analytic ...)
+	TODO: check
 CVE-2023-2107 (A vulnerability, which was classified as critical, was found in IBOS 4 ...)
 	NOT-FOR-US: IBOS
 CVE-2023-2106 (Weak Password Requirements in GitHub repository janeczku/calibre-web p ...)
@@ -80,7 +90,7 @@ CVE-2023-2078
 	RESERVED
 CVE-2021-46880 (x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 er ...)
 	- libressl <itp> (bug #754513)
-CVE-2023-30772
+CVE-2023-30772 (The Linux kernel before 6.2.9 has a race condition and resultant use-a ...)
 	- linux <unfixed> (unimportant)
 	NOTE: https://git.kernel.org/linus/06615d11cc78162dfd5116efb71f29eb29502d37 (6.3-rc4)
 	NOTE: CONFIG_CHARGER_DA9150 not enabled in Debian.
@@ -3094,14 +3104,14 @@ CVE-2023-29511
 	RESERVED
 CVE-2023-29510
 	RESERVED
-CVE-2023-29509
-	RESERVED
-CVE-2023-29508
-	RESERVED
-CVE-2023-29507
-	RESERVED
-CVE-2023-29506
-	RESERVED
+CVE-2023-29509 (XWiki Commons are technical libraries common to several other top leve ...)
+	TODO: check
+CVE-2023-29508 (XWiki Commons are technical libraries common to several other top leve ...)
+	TODO: check
+CVE-2023-29507 (XWiki Commons are technical libraries common to several other top leve ...)
+	TODO: check
+CVE-2023-29506 (XWiki Commons are technical libraries common to several other top leve ...)
+	TODO: check
 CVE-2023-29505
 	RESERVED
 CVE-2023-28393
@@ -4078,14 +4088,14 @@ CVE-2023-29216 (In Apache Linkis <=1.3.1, because the parameters are not effe
 	NOT-FOR-US: Apache Linkis
 CVE-2023-29215 (In Apache Linkis <=1.3.1, due to the lack of effective filtering of ...)
 	NOT-FOR-US: Apache Linkis
-CVE-2023-29214
-	RESERVED
+CVE-2023-29214 (XWiki Commons are technical libraries common to several other top leve ...)
+	TODO: check
 CVE-2023-29213
 	RESERVED
-CVE-2023-29212
-	RESERVED
-CVE-2023-29211
-	RESERVED
+CVE-2023-29212 (XWiki Commons are technical libraries common to several other top leve ...)
+	TODO: check
+CVE-2023-29211 (XWiki Commons are technical libraries common to several other top leve ...)
+	TODO: check
 CVE-2023-29210 (XWiki Commons are technical libraries common to several other top leve ...)
 	TODO: check
 CVE-2023-29209 (XWiki Commons are technical libraries common to several other top leve ...)
@@ -16102,8 +16112,8 @@ CVE-2022-48314
 	RESERVED
 CVE-2022-48313
 	RESERVED
-CVE-2022-48312
-	RESERVED
+CVE-2022-48312 (The HwPCAssistant module has the out-of-bounds read/write vulnerabilit ...)
+	TODO: check
 CVE-2023-25194 (A possible security vulnerability has been identified in Apache Kafka  ...)
 	- kafka <itp> (bug #786460)
 CVE-2022-4902 (A vulnerability classified as problematic has been found in eXo Chat A ...)
@@ -43998,8 +44008,8 @@ CVE-2022-43130
 	RESERVED
 CVE-2022-43129
 	RESERVED
-CVE-2022-43128
-	RESERVED
+CVE-2022-43128 (Dreamer CMS 4.0.1 allows SQL injection via ArchivesMapper.xml. ...)
+	TODO: check
 CVE-2022-43127 (Online Diagnostic Lab Management System v1.0 was discovered to contain ...)
 	NOT-FOR-US: Online Diagnostic Lab Management System
 CVE-2022-43126 (Online Diagnostic Lab Management System v1.0 was discovered to contain ...)
@@ -50076,8 +50086,8 @@ CVE-2022-40948
 	RESERVED
 CVE-2022-40947
 	RESERVED
-CVE-2022-40946
-	RESERVED
+CVE-2022-40946 (On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, i ...)
+	TODO: check
 CVE-2022-40945
 	RESERVED
 CVE-2022-40944 (Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection v ...)
@@ -55362,10 +55372,10 @@ CVE-2022-38843 (EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload
 	NOT-FOR-US: EspoCRM
 CVE-2022-38842
 	RESERVED
-CVE-2022-38841
-	RESERVED
-CVE-2022-38840
-	RESERVED
+CVE-2022-38841 (Linksys AX3200 1.1.00 is vulnerable to OS command injection by authent ...)
+	TODO: check
+CVE-2022-38840 (cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable  ...)
+	TODO: check
 CVE-2022-38839
 	RESERVED
 CVE-2022-38838
@@ -58759,8 +58769,7 @@ CVE-2022-37706 (enlightenment_sys in Enlightenment before 0.25.4 allows local us
 	- e17 0.25.4-1
 	NOTE: https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit
 	NOTE: https://git.enlightenment.org/enlightenment/enlightenment/commit/cc7faeccf77fef8b0ae70e312a21e4cde087e141
-CVE-2022-37705
-	RESERVED
+CVE-2022-37705 (A privilege escalation flaw was found in Amanda 3.5.1 in which the bac ...)
 	- amanda 1:3.5.1-10 (bug #1029829)
 	[bullseye] - amanda <no-dsa> (Minor issue)
 	[buster] - amanda <no-dsa> (Minor issue)
@@ -58769,8 +58778,7 @@ CVE-2022-37705
 	NOTE: https://marc.info/?l=amanda-hackers&m=167437716918603&w=2
 	NOTE: https://github.com/zmanda/amanda/pull/196
 	NOTE: https://github.com/zmanda/amanda/commit/43c5b32f46186f3ed78fe6c7503096fa9ad1236c
-CVE-2022-37704
-	RESERVED
+CVE-2022-37704 (Amanda 3.5.1 allows privilege escalation from the regular user backup  ...)
 	{DLA-3330-1}
 	- amanda 1:3.5.1-10 (bug #1029829)
 	[bullseye] - amanda <no-dsa> (Minor issue)
@@ -59852,8 +59860,8 @@ CVE-2022-37308 (OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-
 	NOT-FOR-US: OX App Suite
 CVE-2022-37307 (OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet,  ...)
 	NOT-FOR-US: OX App Suite
-CVE-2022-37306
-	RESERVED
+CVE-2022-37306 (OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger. ...)
+	TODO: check
 CVE-2022-37305 (The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicle ...)
 	NOT-FOR-US: Remote Keyless Entry (RKE) receiving unit on Honda vehicles
 CVE-2022-36426
@@ -60106,8 +60114,8 @@ CVE-2022-37257 (Prototype pollution vulnerability in function convertLater in np
 	NOT-FOR-US: stealjs
 CVE-2022-37256
 	RESERVED
-CVE-2022-37255
-	RESERVED
+CVE-2022-37255 (TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed vi ...)
+	TODO: check
 CVE-2022-37254 (DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) via Backg ...)
 	NOT-FOR-US: DolphinPHP
 CVE-2022-37253 (Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 al ...)
@@ -60244,8 +60252,7 @@ CVE-2022-37188
 	RESERVED
 CVE-2022-37187
 	RESERVED
-CVE-2022-37186 [Session destroyed on portal but still valid on handlers]
-	RESERVED
+CVE-2022-37186 (In LemonLDAP::NG before 2.0.15. some sessions are not deleted when the ...)
 	{DLA-3287-1}
 	- lemonldap-ng 2.0.15+ds-1
 	[bullseye] - lemonldap-ng 2.0.11+ds-4+deb11u2
@@ -68745,14 +68752,14 @@ CVE-2022-34130
 	RESERVED
 CVE-2022-34129
 	RESERVED
-CVE-2022-34128
-	RESERVED
-CVE-2022-34127
-	RESERVED
-CVE-2022-34126
-	RESERVED
-CVE-2022-34125
-	RESERVED
+CVE-2022-34128 (The Cartography (aka positions) plugin before 6.0.1 for GLPI allows re ...)
+	TODO: check
+CVE-2022-34127 (The Managentities plugin before 4.0.2 for GLPI allows reading local fi ...)
+	TODO: check
+CVE-2022-34126 (The Activity plugin before 3.1.1 for GLPI allows reading local files v ...)
+	TODO: check
+CVE-2022-34125 (front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows at ...)
+	TODO: check
 CVE-2022-34124
 	RESERVED
 CVE-2022-34123
@@ -80088,8 +80095,8 @@ CVE-2022-30078 (NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.
 	NOT-FOR-US: Netgear
 CVE-2022-30077
 	RESERVED
-CVE-2022-30076
-	RESERVED
+CVE-2022-30076 (ENTAB ERP 1.0 allows attackers to discover users' full names via a bru ...)
+	TODO: check
 CVE-2022-30075 (In TP-Link Router AX50 firmware 210730 and older, import of a maliciou ...)
 	NOT-FOR-US: TP-Link
 CVE-2022-30074
@@ -85043,8 +85050,8 @@ CVE-2022-28355 (randomUUID in Scala.js before 1.10.0 generates predictable value
 	NOT-FOR-US: Scala.js
 CVE-2022-28354
 	RESERVED
-CVE-2022-28353
-	RESERVED
+CVE-2022-28353 (In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL ...)
+	TODO: check
 CVE-2022-1210 (A vulnerability classified as problematic was found in LibTIFF 4.3.0.  ...)
 	- tiff <unfixed> (unimportant)
 	[bullseye] - tiff <no-dsa> (Minor issue)
@@ -106779,8 +106786,7 @@ CVE-2021-4159 (A vulnerability was found in the Linux kernel's EBPF verifier whe
 	- linux 5.7.6-1
 	[stretch] - linux <ignored> (Too risky to backport, and mitigated by default)
 	NOTE: Fixed by: https://git.kernel.org/linus/294f2fc6da27620a506e6c050241655459ccd6bd (5.7-rc1)
-CVE-2021-45464 [hypervisor escape and host code execution]
-	RESERVED
+CVE-2021-45464 (kvmtool through 39181fc allows an out-of-bounds write, related to virt ...)
 	- kvmtool <removed> (bug #1006290)
 	NOTE: https://www.kalmarunionen.dk/writeups/2021/hxp-2021/lkvm/
 CVE-2021-45463 (load_cache in GEGL before 0.4.34 allows shell expansion when a pathnam ...)
@@ -114538,8 +114544,7 @@ CVE-2021-43614
 	RESERVED
 CVE-2021-43613
 	RESERVED
-CVE-2021-43612 [crash in SONMP decoder]
-	RESERVED
+CVE-2021-43612 (In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decod ...)
 	{DLA-3389-1}
 	- lldpd 1.0.13-1
 	[bullseye] - lldpd 1.0.11-1+deb11u1
@@ -128073,8 +128078,8 @@ CVE-2021-39297 (Potential vulnerabilities have been identified in UEFI firmware
 	NOT-FOR-US: HP
 CVE-2021-39296 (In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass auth ...)
 	NOT-FOR-US: OpenBMC
-CVE-2021-39295
-	RESERVED
+CVE-2021-39295 (In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a den ...)
+	TODO: check
 CVE-2021-3727 (# Vulnerability in `rand-quote` and `hitokoto` plugins **Description** ...)
 	NOT-FOR-US: ohmyzsh
 CVE-2021-3726 (# Vulnerability in `title` function **Description**: the `title` funct ...)
@@ -135163,8 +135168,8 @@ CVE-2021-36522
 	RESERVED
 CVE-2021-36521
 	RESERVED
-CVE-2021-36520
-	RESERVED
+CVE-2021-36520 (A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a  ...)
+	TODO: check
 CVE-2021-36519
 	RESERVED
 CVE-2021-36518
@@ -140435,8 +140440,7 @@ CVE-2021-34339 (Ming 0.4.8 has an out-of-bounds buffer access issue in the funct
 CVE-2021-34338 (Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function ...)
 	- ming <removed>
 	NOTE: https://github.com/libming/libming/issues/201
-CVE-2021-34337 [password checking timing attack in administrative REST API]
-	RESERVED
+CVE-2021-34337 (An issue was discovered in Mailman Core before 3.3.5. An attacker with ...)
 	- mailman3 3.3.7-1 (bug #1004934)
 	[bullseye] - mailman3 <no-dsa> (Minor issue)
 	[buster] - mailman3 <no-dsa> (Minor issue; will be fixed via point release)
@@ -141181,8 +141185,8 @@ CVE-2021-33992
 	RESERVED
 CVE-2021-33991
 	RESERVED
-CVE-2021-33990
-	RESERVED
+CVE-2021-33990 (Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&Curre ...)
+	TODO: check
 CVE-2021-33989
 	RESERVED
 CVE-2021-33988 (Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2 ...)
@@ -151628,8 +151632,7 @@ CVE-2021-30154 (An issue was discovered in MediaWiki before 1.31.12 and 1.32.x t
 	[stretch] - mediawiki <not-affected> (Vulnerable code introduced later)
 	NOTE: https://phabricator.wikimedia.org/T278014
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/674083/
-CVE-2021-30153
-	RESERVED
+CVE-2021-30153 (An issue was discovered in the VisualEditor extension in MediaWiki bef ...)
 	- mediawiki 1:1.35.2-1
 	[buster] - mediawiki <not-affected> (Vulnerable code not present)
 	[stretch] - mediawiki <not-affected> (Vulnerable code not present)
@@ -182912,8 +182915,7 @@ CVE-2020-29009
 	RESERVED
 CVE-2020-29008
 	RESERVED
-CVE-2020-29007
-	RESERVED
+CVE-2020-29007 (The Score extension through 0.3.0 for MediaWiki has a remote code exec ...)
 	NOT-FOR-US: Score MediaWiki extension
 	NOTE: https://seqred.pl/en/cve-2020-29007-remote-code-execution-in-mediawiki-score/
 	NOTE: https://phabricator.wikimedia.org/T257062
@@ -187814,8 +187816,7 @@ CVE-2020-28165 (The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbit
 	NOT-FOR-US: EasyCorp ZenTao PMS
 CVE-2020-28164
 	RESERVED
-CVE-2020-28163
-	RESERVED
+CVE-2020-28163 (libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer der ...)
 	- dwarfutils 20201201-1
 	[buster] - dwarfutils <ignored> (Minor issue)
 	[stretch] - dwarfutils <ignored> (Minor issue)
@@ -190214,8 +190215,7 @@ CVE-2020-27547
 	RESERVED
 CVE-2020-27546
 	RESERVED
-CVE-2020-27545
-	RESERVED
+CVE-2020-27545 (libdwarf before 20201017 has a one-byte out-of-bounds read because of  ...)
 	- dwarfutils 20201201-1
 	[buster] - dwarfutils <ignored> (Minor issue)
 	[stretch] - dwarfutils <ignored> (Minor issue)
@@ -212874,8 +212874,7 @@ CVE-2020-17356
 	RESERVED
 CVE-2020-17355 (Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23. ...)
 	NOT-FOR-US: Arista
-CVE-2020-17354
-	RESERVED
+CVE-2020-17354 (LilyPond before 2.24 allows attackers to bypass the -dsafe protection  ...)
 	- lilypond 2.22.1-1
 	[bullseye] - lilypond <ignored> (Unfixable, marked as insecure in later uploads)
 	[buster] - lilypond <ignored> (Unfixable, marked as insecure in later uploads)
@@ -272111,16 +272110,14 @@ CVE-2019-14946 (The ultimate-member plugin before 2.0.52 for WordPress has XSS r
 	NOT-FOR-US: ultimate-member plugin for WordPress
 CVE-2019-14945 (The ultimate-member plugin before 2.0.54 for WordPress has XSS. ...)
 	NOT-FOR-US: ultimate-member plugin for WordPress
-CVE-2019-14944 [Multiple Command-Line Flag Injection Vulnerabilities]
-	RESERVED
+CVE-2019-14944 (An issue was discovered in GitLab Community and Enterprise Edition bef ...)
 	[experimental] - gitlab 11.11.8+dfsg-1
 	- gitlab 12.6.8-3 (bug #934708)
 	NOTE: https://about.gitlab.com/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/
 CVE-2019-14943 (An issue was discovered in GitLab Community and Enterprise Edition 12. ...)
 	- gitlab <not-affected> (Only affects GitLab CE/EE 12.0 and later)
 	NOTE: https://about.gitlab.com/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/
-CVE-2019-14942 [Insecure Cookie Handling on GitLab Pages]
-	RESERVED
+CVE-2019-14942 (An issue was discovered in GitLab Community and Enterprise Edition bef ...)
 	[experimental] - gitlab 11.11.8+dfsg-1
 	- gitlab 12.6.8-3 (bug #934708)
 	NOTE: https://about.gitlab.com/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/
@@ -320981,8 +320978,7 @@ CVE-2018-17886 (An issue was discovered in JEESNS 1.3. The XSS filter in com.lxi
 	NOT-FOR-US: JEESNS
 CVE-2018-17885
 	RESERVED
-CVE-2018-17883
-	RESERVED
+CVE-2018-17883 (An issue was discovered in Open Ticket Request System (OTRS) 6.0.x bef ...)
 	- otrs2 6.0.12-1
 	[stretch] - otrs2 <not-affected> (Only affects 6.x)
 	[jessie] - otrs2 <not-affected> (Only affects 6.x)
@@ -321757,14 +321753,12 @@ CVE-2018-17539 (The BGP daemon (bgpd) in all IP Infusion ZebOS versions to 7.10.
 	NOT-FOR-US: BGP daemon (bgpd) in IP Infusion ZebOS and OcNOS
 CVE-2018-17538 (** DISPUTED ** Axon (formerly TASER International) Evidence Sync 3.15. ...)
 	NOT-FOR-US: Axon Evidence Sync
-CVE-2018-17537 [Persistent XSS package.json]
-	RESERVED
+CVE-2018-17537 (An issue was discovered in GitLab Community and Enterprise Edition bef ...)
 	[experimental] - gitlab 11.1.8+dfsg-1
 	- gitlab 11.1.8+dfsg-2
 	[stretch] - gitlab <not-affected> (Only affects 10.4 and later)
 	NOTE: https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17536 [Persistent XSS merge request project import]
-	RESERVED
+CVE-2018-17536 (An issue was discovered in GitLab Community and Enterprise Edition bef ...)
 	[experimental] - gitlab 11.1.8+dfsg-1
 	- gitlab 11.1.8+dfsg-2
 	[stretch] - gitlab <not-affected> (Only affects 10.4 and later)
@@ -321982,42 +321976,35 @@ CVE-2018-17456 (Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2
 	NOTE: https://git.kernel.org/pub/scm/git/git.git/commit/?id=273c61496f88c6495b886acb1041fe57965151da
 	NOTE: https://git.kernel.org/pub/scm/git/git.git/commit/?id=a124133e1e6ab5c7a9fef6d0e6bcb084e3455b46
 	NOTE: https://git.kernel.org/pub/scm/git/git.git/commit/?id=1a7fd1fb2998002da6e9ff2ee46e1bdd25ee8404
-CVE-2018-17455 [IDOR merge request approvals]
-	RESERVED
+CVE-2018-17455 (An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11 ...)
 	[experimental] - gitlab 11.1.8+dfsg-1
 	- gitlab 11.1.8+dfsg-2
 	NOTE: https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17454 [Persistent XSS on issue details]
-	RESERVED
+CVE-2018-17454 (An issue was discovered in GitLab Community and Enterprise Edition bef ...)
 	[experimental] - gitlab 11.1.8+dfsg-1
 	- gitlab 11.1.8+dfsg-2
 	[stretch] - gitlab <not-affected> (Only affects 9.3 and later)
 	NOTE: https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17453 [GRPC::Unknown logging token disclosure]
-	RESERVED
+CVE-2018-17453 (An issue was discovered in GitLab Community and Enterprise Edition bef ...)
 	[experimental] - gitlab 11.1.8+dfsg-1
 	- gitlab 11.1.8+dfsg-2
 	[stretch] - gitlab <not-affected> (Only affects 10.4 and later)
 	NOTE: https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17452 [validate_localhost function in url_blocker.rb could be bypassed]
-	RESERVED
+CVE-2018-17452 (An issue was discovered in GitLab Community and Enterprise Edition bef ...)
 	[experimental] - gitlab 11.1.8+dfsg-1
 	- gitlab 11.1.8+dfsg-2
 	NOTE: https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17451 [Slack integration CSRF Oauth2]
-	RESERVED
+CVE-2018-17451 (An issue was discovered in GitLab Community and Enterprise Edition bef ...)
 	[experimental] - gitlab 11.1.8+dfsg-1
 	- gitlab 11.1.8+dfsg-2
 	[stretch] - gitlab <not-affected> (Only affects 9.4 and later)
 	NOTE: https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17450 [SSRF GCP access token disclosure]
-	RESERVED
+CVE-2018-17450 (An issue was discovered in GitLab Community and Enterprise Edition bef ...)
 	[experimental] - gitlab 11.1.8+dfsg-1
 	- gitlab 11.1.8+dfsg-2
 	[stretch] - gitlab <not-affected> (Only affects 10.2 and later)
 	NOTE: https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17449 [Confidential information disclosure in events API endpoint]
-	RESERVED
+CVE-2018-17449 (An issue was discovered in GitLab Community and Enterprise Edition bef ...)
 	[experimental] - gitlab 11.1.8+dfsg-1
 	- gitlab 11.1.8+dfsg-2
 	[stretch] - gitlab <not-affected> (Only affects 9.3 and later)
@@ -327331,8 +327318,7 @@ CVE-2018-15475
 	RESERVED
 CVE-2018-15474 (** DISPUTED ** CSV Injection (aka Excel Macro Injection or Formula Inj ...)
 	NOTE: Dokuwiki non-issue
-CVE-2018-15472 [Diff formatter DoS in Sidekiq jobs]
-	RESERVED
+CVE-2018-15472 (An issue was discovered in GitLab Community and Enterprise Edition bef ...)
 	[experimental] - gitlab 11.1.8+dfsg-1
 	- gitlab 11.1.8+dfsg-2
 	NOTE: https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a05456b48000a9df119924f158450ca33d5524b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a05456b48000a9df119924f158450ca33d5524b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230416/afa0ab27/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list