[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Dec 21 14:44:06 GMT 2023
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
66bc6291 by Moritz Muehlenhoff at 2023-12-21T15:43:36+01:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,13 @@
+CVE-2023-48291
+ - airflow <itp> (bug #819700)
+CVE-2023-47265
+ - airflow <itp> (bug #819700)
+CVE-2023-49920
+ - airflow <itp> (bug #819700)
+CVE-2023-50783
+ - airflow <itp> (bug #819700)
+CVE-2023-51656
+ NOT-FOR-US: Apache IoTDB
CVE-2023-XXXX [RUSTSEC-2023-0075]
- rust-unsafe-libyaml <unfixed>
NOTE: https://rustsec.org/advisories/RUSTSEC-2023-0075.html
@@ -50,7 +60,7 @@ CVE-2023-48433 (Online Voting System Project v1.0 is vulnerable to multiple Unau
CVE-2023-47093 (An issue was discovered in Stormshield Network Security (SNS) 4.0.0 th ...)
NOT-FOR-US: Stormshield Network Security (SNS)
CVE-2023-46131 (Grails is a framework used to build web applications with the Groovy p ...)
- TODO: check
+ - grails <itp> (bug #473213)
CVE-2023-45703 (HCL Launch may mishandle input validation of an uploaded archive file ...)
NOT-FOR-US: HCL
CVE-2023-45700 (HCL Launch is vulnerable to HTML injection. This vulnerability may all ...)
@@ -97,7 +107,7 @@ CVE-2023-51457 (Adobe Experience Manager versions 6.5.18 and earlier are affecte
CVE-2023-50628 (Buffer Overflow vulnerability in libming version 0.4.8, allows attacke ...)
- ming <removed>
CVE-2023-50249 (Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Reg ...)
- TODO: check
+ NOT-FOR-US: Sentry-Javascript
CVE-2023-50044 (Buffer Overflow vulnerability in Cesanta MJS version 2.22.0, allows at ...)
NOT-FOR-US: Cesenta MJS
CVE-2023-49825 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
@@ -153,7 +163,7 @@ CVE-2023-40204 (Unrestricted Upload of File with Dangerous Type vulnerability in
CVE-2023-40010 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
NOT-FOR-US: WordPress plugin
CVE-2023-3742 (Insufficient policy enforcement in ADB in Google Chrome on ChromeOS pr ...)
- TODO: check
+ NOT-FOR-US: Google Chrome on ChromeOS
CVE-2023-38519 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
NOT-FOR-US: WordPress plugin
CVE-2023-38513 (Authorization Bypass Through User-Controlled Key vulnerability in Jord ...)
@@ -38415,11 +38425,11 @@ CVE-2023-29489 (An issue was discovered in cPanel before 11.109.9999.116. XSS ca
CVE-2023-29488
RESERVED
CVE-2023-29487 (An issue was discovered in Heimdal Thor agent versions 3.4.2 and befor ...)
- TODO: check
+ NOT-FOR-US: Heimdal Thor
CVE-2023-29486 (An issue was discovered in Heimdal Thor agent versions 3.4.2 and befor ...)
- TODO: check
+ NOT-FOR-US: Heimdal Thor
CVE-2023-29485 (An issue was discovered in Heimdal Thor agent versions 3.4.2 and befor ...)
- TODO: check
+ NOT-FOR-US: Heimdal Thor
CVE-2023-29484 (In Terminalfour before 8.3.16, misconfigured LDAP users are able to lo ...)
NOT-FOR-US: Terminalfour
CVE-2023-29483
@@ -65915,7 +65925,7 @@ CVE-2022-41834
CVE-2020-36611 (Incorrect Default Permissions vulnerability in Hitachi Tuning Manager ...)
NOT-FOR-US: Hitachi
CVE-2023-0011 (A flaw in the input validation in TOBY-L2 allows a user to execute arb ...)
- TODO: check
+ NOT-FOR-US: TOBY-L2
CVE-2022-47193
RESERVED
CVE-2022-47192 (Generex UPS CS141 below 2.06 version, could allow a remote attacker to ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66bc6291e062b20d168e8c070df0adca56b2c91f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66bc6291e062b20d168e8c070df0adca56b2c91f
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231221/393f5f28/attachment.htm>
More information about the debian-security-tracker-commits
mailing list