[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Jan 30 13:35:33 GMT 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1021ab02 by Moritz Muehlenhoff at 2023-01-30T14:35:08+01:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -359,9 +359,9 @@ CVE-2023-24625
 CVE-2023-24624
 	RESERVED
 CVE-2023-24623 (Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to th ...)
-	TODO: check
+	NOT-FOR-US: Paranoidhttp
 CVE-2023-24622 (isInList in the safeurl-python package before 1.2 for Python has an in ...)
-	TODO: check
+	NOT-FOR-US: safeurl-python
 CVE-2023-24621
 	RESERVED
 CVE-2023-24620
@@ -381,7 +381,7 @@ CVE-2023-24614
 CVE-2023-24613
 	RESERVED
 CVE-2023-24612 (The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allo ...)
-	TODO: check
+	NOT-FOR-US: MediaWiki PdfBook extension
 CVE-2023-24611
 	RESERVED
 CVE-2023-24610
@@ -393,7 +393,7 @@ CVE-2023-24608
 CVE-2023-0573
 	RESERVED
 CVE-2023-0572 (Unchecked Error Condition in GitHub repository froxlor/froxlor prior t ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2022-4898
 	RESERVED
 CVE-2022-48304
@@ -469,9 +469,9 @@ CVE-2023-24598
 CVE-2023-24597
 	RESERVED
 CVE-2023-0566 (Static Code Injection in GitHub repository froxlor/froxlor prior to 2. ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2023-0565 (Business Logic Errors in GitHub repository froxlor/froxlor prior to 2. ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2023-0564 (Weak Password Requirements in GitHub repository froxlor/froxlor prior  ...)
 	- froxlor <itp> (bug #581792)
 CVE-2023-0563 (A vulnerability classified as problematic has been found in PHPGurukul ...)
@@ -485,9 +485,9 @@ CVE-2023-0561 (A vulnerability, which was classified as critical, was found in S
 CVE-2023-0560 (A vulnerability, which was classified as critical, has been found in S ...)
 	NOT-FOR-US: SourceCodester Online Tours & Travels Management System
 CVE-2016-15022 (A vulnerability was found in mosbth cimage up to 0.7.18. It has been d ...)
-	TODO: check
+	NOT-FOR-US: mosbth cimage
 CVE-2009-10003 (A vulnerability was found in capnsquarepants wordcraft up to 0.6. It h ...)
-	TODO: check
+	NOT-FOR-US: capnsquarepants wordcraft
 CVE-2023-0559
 	RESERVED
 CVE-2023-0558 (The ContentStudio plugin for WordPress is vulnerable to authorization  ...)
@@ -1010,7 +1010,7 @@ CVE-2023-22315
 CVE-2023-0456
 	RESERVED
 CVE-2023-0455 (Unrestricted Upload of File with Dangerous Type in GitHub repository u ...)
-	TODO: check
+	NOT-FOR-US: unilogies/bumsys
 CVE-2023-0454
 	RESERVED
 CVE-2023-0453



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1021ab021561b94d6fd717958430efa4b804e45b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1021ab021561b94d6fd717958430efa4b804e45b
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230130/d86cb81c/attachment.htm>


More information about the debian-security-tracker-commits mailing list