[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2023-28864,chef: Link to CVE description, impact, remediation

Markus Koschany (@apo) apo at debian.org
Sun Jul 30 17:20:01 BST 2023



Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b2937ef2 by Markus Koschany at 2023-07-30T18:14:56+02:00
CVE-2023-28864,chef: Link to CVE description, impact, remediation

- - - - -
69777e69 by Markus Koschany at 2023-07-30T18:19:38+02:00
Add chef to dla-needed.txt

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -16736,6 +16736,7 @@ CVE-2023-28865
 	RESERVED
 CVE-2023-28864 (Progress Chef Infra Server before 15.7 allows a local attacker to expl ...)
 	- chef <removed>
+	NOTE: https://blog.mondoo.com/chef-infra-server-cve-2023-28864-impact-and-remediation
 CVE-2023-28863 (AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of  ...)
 	NOT-FOR-US: AMI
 CVE-2023-28862 (An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session I ...)


=====================================
data/dla-needed.txt
=====================================
@@ -28,6 +28,10 @@ cairosvg (gladk)
   NOTE: 20230323: Added by Front-Desk (gladk)
   NOTE: 20230411: Proposed solution for CVE-2023-27586 in Buster to backport the --unsafe switch, introduced in 1.0.21, might work (dleidert/inactive)
 --
+chef
+  NOTE: 20230730: Added by Front-Desk (apo)
+  NOTE: 20230730: We could just change the directory permissions to fix this problem. (apo)
+--
 cinder
   NOTE: 20230525: Added by Front-Desk (lamby)
   NOTE: 20230525: NB. CVE-2023-2088 filed against python-glance-store, python-os-brick, nova and cinder.



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9b292c0b0fb6fa7a0a32a20c64568eed8d52dccf...69777e6973ea60298995886e72699fb2d3496513

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9b292c0b0fb6fa7a0a32a20c64568eed8d52dccf...69777e6973ea60298995886e72699fb2d3496513
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230730/4364d33e/attachment.htm>


More information about the debian-security-tracker-commits mailing list