[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Dec 21 14:44:06 GMT 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
66bc6291 by Moritz Muehlenhoff at 2023-12-21T15:43:36+01:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,13 @@
+CVE-2023-48291
+	- airflow <itp> (bug #819700)
+CVE-2023-47265
+	- airflow <itp> (bug #819700)
+CVE-2023-49920
+	- airflow <itp> (bug #819700)
+CVE-2023-50783
+	- airflow <itp> (bug #819700)
+CVE-2023-51656
+	NOT-FOR-US: Apache IoTDB
 CVE-2023-XXXX [RUSTSEC-2023-0075]
 	- rust-unsafe-libyaml <unfixed>
 	NOTE: https://rustsec.org/advisories/RUSTSEC-2023-0075.html
@@ -50,7 +60,7 @@ CVE-2023-48433 (Online Voting System Project v1.0 is vulnerable to multiple Unau
 CVE-2023-47093 (An issue was discovered in Stormshield Network Security (SNS) 4.0.0 th ...)
 	NOT-FOR-US: Stormshield Network Security (SNS)
 CVE-2023-46131 (Grails is a framework used to build web applications with the Groovy p ...)
-	TODO: check
+	- grails <itp> (bug #473213)
 CVE-2023-45703 (HCL Launch may mishandle input validation of an uploaded archive file  ...)
 	NOT-FOR-US: HCL
 CVE-2023-45700 (HCL Launch is vulnerable to HTML injection. This vulnerability may all ...)
@@ -97,7 +107,7 @@ CVE-2023-51457 (Adobe Experience Manager versions 6.5.18 and earlier are affecte
 CVE-2023-50628 (Buffer Overflow vulnerability in libming version 0.4.8, allows attacke ...)
 	- ming <removed>
 CVE-2023-50249 (Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Reg ...)
-	TODO: check
+	NOT-FOR-US: Sentry-Javascript
 CVE-2023-50044 (Buffer Overflow vulnerability in Cesanta MJS version 2.22.0, allows at ...)
 	NOT-FOR-US: Cesenta MJS
 CVE-2023-49825 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
@@ -153,7 +163,7 @@ CVE-2023-40204 (Unrestricted Upload of File with Dangerous Type vulnerability in
 CVE-2023-40010 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2023-3742 (Insufficient policy enforcement in ADB in Google Chrome on ChromeOS pr ...)
-	TODO: check
+	NOT-FOR-US: Google Chrome on ChromeOS
 CVE-2023-38519 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2023-38513 (Authorization Bypass Through User-Controlled Key vulnerability in Jord ...)
@@ -38415,11 +38425,11 @@ CVE-2023-29489 (An issue was discovered in cPanel before 11.109.9999.116. XSS ca
 CVE-2023-29488
 	RESERVED
 CVE-2023-29487 (An issue was discovered in Heimdal Thor agent versions 3.4.2 and befor ...)
-	TODO: check
+	NOT-FOR-US: Heimdal Thor
 CVE-2023-29486 (An issue was discovered in Heimdal Thor agent versions 3.4.2 and befor ...)
-	TODO: check
+	NOT-FOR-US: Heimdal Thor
 CVE-2023-29485 (An issue was discovered in Heimdal Thor agent versions 3.4.2 and befor ...)
-	TODO: check
+	NOT-FOR-US: Heimdal Thor
 CVE-2023-29484 (In Terminalfour before 8.3.16, misconfigured LDAP users are able to lo ...)
 	NOT-FOR-US: Terminalfour
 CVE-2023-29483
@@ -65915,7 +65925,7 @@ CVE-2022-41834
 CVE-2020-36611 (Incorrect Default Permissions vulnerability in Hitachi Tuning Manager  ...)
 	NOT-FOR-US: Hitachi
 CVE-2023-0011 (A flaw in the input validation in TOBY-L2 allows a user to execute arb ...)
-	TODO: check
+	NOT-FOR-US: TOBY-L2
 CVE-2022-47193
 	RESERVED
 CVE-2022-47192 (Generex UPS CS141 below 2.06 version, could allow a remote attacker to ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66bc6291e062b20d168e8c070df0adca56b2c91f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66bc6291e062b20d168e8c070df0adca56b2c91f
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231221/393f5f28/attachment.htm>


More information about the debian-security-tracker-commits mailing list