[Git][security-tracker-team/security-tracker][master] bullseye/bookworm triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Dec 1 20:54:26 GMT 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a181c888 by Moritz Muehlenhoff at 2023-12-01T21:54:01+01:00
bullseye/bookworm triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11249,6 +11249,7 @@ CVE-2023-5115 [malicious role archive can cause ansible-galaxy to overwrite arbi
 	[bookworm] - ansible-core <no-dsa> (Minor issue)
 	[bullseye] - ansible-core <no-dsa> (Minor issue)
 	- ansible 5.4.0-1
+	[bullseye] - ansible <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2233810
 	NOTE: https://github.com/ansible/ansible/pull/81780
 	NOTE: https://github.com/ansible/ansible/commit/ddf0311c63287e2d5334770377350c1e0cbfff28
@@ -14847,6 +14848,8 @@ CVE-2023-41537 (phpjabbers Business Directory Script 3.2 is vulnerable to Cross
 	NOT-FOR-US: PHPJabbers
 CVE-2023-41039 (RestrictedPython is a restricted execution environment for Python to r ...)
 	- restrictedpython 6.2-1
+	[bookworm] - restrictedpython <no-dsa> (Minor issue)
+	[bullseye] - restrictedpython <no-dsa> (Minor issue)
 	NOTE: https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-xjw2-6jm9-rf67
 	NOTE: Fixed by: https://github.com/zopefoundation/RestrictedPython/commit/4134aedcff17c977da7717693ed89ce56d54c120
 CVE-2023-40848 (Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Bu ...)
@@ -20928,6 +20931,8 @@ CVE-2023-36818 (Discourse is an open source discussion platform. In affected ver
 	NOT-FOR-US: Discourse
 CVE-2023-36811 (borgbackup is an opensource, deduplicating archiver with compression a ...)
 	- borgbackup 1.2.5-1
+	[bookworm] - borgbackup <ignored> (Minor issue)
+	[bullseye] - borgbackup <ignored> (Minor issue)
 	NOTE: https://github.com/borgbackup/borg/security/advisories/GHSA-8fjr-hghr-4m99
 	NOTE: https://github.com/borgbackup/borg/commit/a2ee13fd341dcd004b4a06b17d6f2fc759327861
 	NOTE: https://github.com/borgbackup/borg/commit/bfead4b288833f890523d8881797ff6b345edaf9
@@ -21654,6 +21659,8 @@ CVE-2023-37280 (Pimcore Admin Classic Bundle provides a Backend UI for Pimcore b
 	NOT-FOR-US: Pimcore Admin Classic Bundle
 CVE-2023-37271 (RestrictedPython is a tool that helps to define a subset of the Python ...)
 	- restrictedpython 6.2-1 (bug #1041429)
+	[bookworm] - restrictedpython <no-dsa> (Minor issue)
+	[bullseye] - restrictedpython <no-dsa> (Minor issue)
 	NOTE: https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-wqc8-x2pr-7jqh
 	NOTE: https://github.com/zopefoundation/RestrictedPython/commit/c8eca66ae49081f0016d2e1f094c3d72095ef531 (master)
 	NOTE: https://github.com/zopefoundation/RestrictedPython/commit/d8c5aa72c5d0ec8eceab635d93d6bc8321116002 (5.3)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a181c8882ebcafac3889b7aa189520e9c023ec14

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a181c8882ebcafac3889b7aa189520e9c023ec14
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231201/abb5eb0d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list