[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2023-50250/cacti: buster not-affected

Sylvain Beucler (@beuc) beuc at debian.org
Sat Dec 23 08:51:08 GMT 2023



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d800e5e6 by Sylvain Beucler at 2023-12-23T09:48:25+01:00
CVE-2023-50250/cacti: buster not-affected

- - - - -
a65dc34d by Sylvain Beucler at 2023-12-23T09:49:01+01:00
CVE-2023-50569/cacti: most likely duplicate of CVE-2023-50250

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -104,6 +104,7 @@ CVE-2023-50708 (yii2-authclient is an extension that adds OpenID, OAuth, OAuth2
 CVE-2023-50569 (Reflected Cross Site Scripting (XSS) vulnerability in Cacti v1.2.25, a ...)
 	- cacti <unfixed>
 	NOTE: https://gist.github.com/ISHGARD-2/a6b57de899f977e2af41780e7428b4bf
+	NOTE: Exact same text as GHSA-xwqc-7jc4-xm73 / CVE-2023-50250.
 CVE-2023-50259 (Medusa is an automatic video library manager for TV shows. Versions pr ...)
 	TODO: check
 CVE-2023-50258 (Medusa is an automatic video library manager for TV shows. Versions pr ...)
@@ -112,7 +113,9 @@ CVE-2023-50254 (Deepin Linux's default document reader `deepin-reader` software
 	- deepin-reader <itp> (bug #970218)
 CVE-2023-50250 (Cacti is an open source operational monitoring and fault management fr ...)
 	- cacti <unfixed>
+	[buster] - cacti <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-xwqc-7jc4-xm73
+	NOTE: Introduced by: https://github.com/Cacti/cacti/commit/27a36d48e1cea172b0750c970324208b39d2bec5 (release/1.2.23)
 CVE-2023-50147 (There is an arbitrary command execution vulnerability in the setDiagno ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2023-49792 (Nextcloud Server provides data storage for Nextcloud, an open source c ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/78055871a641cd52c6b9248fa85330068f6e10b1...a65dc34d41a35fd4229e03ad1e7682609d53ae34

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/78055871a641cd52c6b9248fa85330068f6e10b1...a65dc34d41a35fd4229e03ad1e7682609d53ae34
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231223/94a725aa/attachment.htm>


More information about the debian-security-tracker-commits mailing list