[Git][security-tracker-team/security-tracker][master] new guava-libraries issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Jun 22 16:52:02 BST 2023
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1eabeb97 by Moritz Muehlenhoff at 2023-06-22T17:51:31+02:00
new guava-libraries issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -664,7 +664,9 @@ CVE-2023-32024 (Microsoft Power Apps Spoofing Vulnerability)
CVE-2023-31671 (PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via P ...)
NOT-FOR-US: PrestaShop postfinance
CVE-2023-2976 (Use of Java's default temporary directory for file creation in `FileBa ...)
- TODO: check
+ - guava-libraries <unfixed>
+ NOTE: https://github.com/google/guava/releases/tag/v32.0.0
+ NOTE: https://github.com/google/guava/issues/2575
CVE-2023-35149 (A missing permission check in Jenkins Digital.ai App Management Publis ...)
NOT-FOR-US: Jenkins plugin
CVE-2023-35148 (A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.a ...)
@@ -243859,7 +243861,9 @@ CVE-2020-8910 (A URL parsing issue in goog.uri of the Google Closure Library ver
CVE-2020-8909
RESERVED
CVE-2020-8908 (A temp directory creation vulnerability exists in all versions of Guav ...)
- NOT-FOR-US: Google Guava
+ - guava-libraries <unfixed>
+ NOTE: https://github.com/google/guava/releases/tag/v32.0.0
+ NOTE: https://github.com/google/guava/issues/2575
CVE-2020-8907 (A vulnerability in Google Cloud Platform's guest-oslogin versions betw ...)
- google-compute-image-packages <removed> (bug #987353)
[buster] - google-compute-image-packages <ignored> (Minor issue)
@@ -349129,7 +349133,7 @@ CVE-2018-10239 (A privilege escalation vulnerability in the "support access" fea
CVE-2018-10238 (bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affec ...)
NOT-FOR-US: skarg BACnet Protocol Stack
CVE-2018-10237 (Unbounded memory allocation in Google Guava 11.0 through 24.x before 2 ...)
- NOT-FOR-US: Google Guava
+ - guava-libraries 29.0-1
CVE-2018-10236 (POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code vi ...)
NOT-FOR-US: POSCMS
CVE-2018-10235 (POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code vi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1eabeb975a37b7f3a0df2759eddb25e5fc4de149
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1eabeb975a37b7f3a0df2759eddb25e5fc4de149
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230622/fb359311/attachment.htm>
More information about the debian-security-tracker-commits
mailing list