[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jun 22 21:12:33 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e0a3ba0a by security tracker role at 2023-06-22T20:12:19+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,101 @@
+CVE-2023-3326 (pam_krb5 authenticates a user by essentially running kinit with the pa ...)
+	TODO: check
+CVE-2023-3256 (Advantech R-SeeNet  versions 2.4.22  allows low-level users to access  ...)
+	TODO: check
+CVE-2023-36371 (An issue in the GDKfree component of MonetDB Server v11.45.17 and v11. ...)
+	TODO: check
+CVE-2023-36370 (An issue in the gc_col component of MonetDB Server v11.45.17 and v11.4 ...)
+	TODO: check
+CVE-2023-36369 (An issue in the list_append component of MonetDB Server v11.45.17 and  ...)
+	TODO: check
+CVE-2023-36368 (An issue in the cs_bind_ubat component of MonetDB Server v11.45.17 and ...)
+	TODO: check
+CVE-2023-36367 (An issue in the BLOBcmp component of MonetDB Server v11.45.17 and v11. ...)
+	TODO: check
+CVE-2023-36366 (An issue in the log_create_delta component of MonetDB Server v11.45.17 ...)
+	TODO: check
+CVE-2023-36365 (An issue in the sql_trans_copy_key component of MonetDB Server v11.45. ...)
+	TODO: check
+CVE-2023-36364 (An issue in the rel_deps component of MonetDB Server v11.45.17 and v11 ...)
+	TODO: check
+CVE-2023-36363 (An issue in the __nss_database_lookup component of MonetDB Server v11. ...)
+	TODO: check
+CVE-2023-36362 (An issue in the rel_sequences component of MonetDB Server v11.45.17 an ...)
+	TODO: check
+CVE-2023-36359 (TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND ...)
+	TODO: check
+CVE-2023-36358 (TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR8 ...)
+	TODO: check
+CVE-2023-36357 (An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL ...)
+	TODO: check
+CVE-2023-36356 (TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N ...)
+	TODO: check
+CVE-2023-36355 (TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via t ...)
+	TODO: check
+CVE-2023-36354 (TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/ ...)
+	TODO: check
+CVE-2023-36243 (FLVMeta v1.2.1 was discovered to contain a buffer overflow via the xml ...)
+	TODO: check
+CVE-2023-36239 (libming listswf 0.4.7 was discovered to contain a buffer overflow in t ...)
+	TODO: check
+CVE-2023-36097 (funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via  ...)
+	TODO: check
+CVE-2023-36093 (There is a storage type cross site scripting (XSS) vulnerability in th ...)
+	TODO: check
+CVE-2023-35926 (Backstage is an open platform for building developer portals. The Back ...)
+	TODO: check
+CVE-2023-35918 (Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooComme ...)
+	TODO: check
+CVE-2023-35917 (Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal  ...)
+	TODO: check
+CVE-2023-35174 (Livebook is a web application for writing interactive and collaborativ ...)
+	TODO: check
+CVE-2023-35093 (Broken Access Control vulnerability in StylemixThemes MasterStudy LMS  ...)
+	TODO: check
+CVE-2023-35090 (Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability i ...)
+	TODO: check
+CVE-2023-34939 (Onlyoffice Community Server before v12.5.2 was discovered to contain a ...)
+	TODO: check
+CVE-2023-34927 (Casdoor v1.331.0 and below was discovered to contain a Cross-Site Requ ...)
+	TODO: check
+CVE-2023-34923 (XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in T ...)
+	TODO: check
+CVE-2023-34796 (Cross site scripting (XSS) vulnerabiliy in dmarcts-report-viewer dashb ...)
+	TODO: check
+CVE-2023-34601 (Jeesite before commit 10742d3 was discovered to contain a SQL injectio ...)
+	TODO: check
+CVE-2023-34368 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanb ...)
+	TODO: check
+CVE-2023-34170 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP O ...)
+	TODO: check
+CVE-2023-34028 (Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF \u2 ...)
+	TODO: check
+CVE-2023-34006 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marc ...)
+	TODO: check
+CVE-2023-33997 (Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Robin Wi ...)
+	TODO: check
+CVE-2023-33387 (A reflected cross-site scripting (XSS) vulnerability in DATEV eG Perso ...)
+	TODO: check
+CVE-2023-33323 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Repu ...)
+	TODO: check
+CVE-2023-32960 (Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, Da ...)
+	TODO: check
+CVE-2023-32571 (Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to  ...)
+	TODO: check
+CVE-2023-32239 (Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in ...)
+	TODO: check
+CVE-2023-31868 (Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XS ...)
+	TODO: check
+CVE-2023-31867 (Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.)
+	TODO: check
+CVE-2023-2991 (Fortra Globalscape EFT's administration server suffers from an informa ...)
+	TODO: check
+CVE-2023-2990 (Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial o ...)
+	TODO: check
+CVE-2023-2989 (Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of  ...)
+	TODO: check
+CVE-2023-2611 (Advantech R-SeeNet  versions 2.4.22   is installed with a hidden root- ...)
+	TODO: check
 CVE-2023-34614 (An issue was discovered jmarsden/jsonij thru 0.5.2 allows attackers to ...)
 	TODO: check
 CVE-2023-33842 (IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 r ...)
@@ -4968,8 +5066,8 @@ CVE-2023-31215
 	RESERVED
 CVE-2023-31214
 	RESERVED
-CVE-2023-31213
-	RESERVED
+CVE-2023-31213 (Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability i ...)
+	TODO: check
 CVE-2023-31212
 	RESERVED
 CVE-2023-31211
@@ -7350,8 +7448,8 @@ CVE-2023-1991
 	RESERVED
 CVE-2022-48437 (An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1 ...)
 	- libressl <itp> (bug #754513)
-CVE-2023-30500
-	RESERVED
+CVE-2023-30500 (Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms  ...)
+	TODO: check
 CVE-2023-30499
 	RESERVED
 CVE-2023-30498
@@ -8634,8 +8732,8 @@ CVE-2023-29932 (llvm-project commit fdbc55a5 was discovered to contain a segment
 	NOTE: https://github.com/llvm/llvm-project/issues/58745
 	NOTE: https://github.com/llvm/llvm-project/commit/d35fcf0e97e7bb02381506a71e61ec282b292c50
 	NOTE: Negligible security impact, also see https://llvm.org/docs/Security.html#what-is-considered-a-security-issue
-CVE-2023-29931
-	RESERVED
+CVE-2023-29931 (laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illumi ...)
+	TODO: check
 CVE-2023-29930 (An issue was found in Genesys CIC Polycom phone provisioning TFTP Serv ...)
 	NOT-FOR-US: Genesys
 CVE-2023-29929
@@ -9082,16 +9180,16 @@ CVE-2023-29713 (Cross Site Scripting vulnerability found in Vade Secure Gateway
 	NOT-FOR-US: Vade Secure Gateway
 CVE-2023-29712 (Cross Site Scripting vulnerability found in Vade Secure Gateway allows ...)
 	NOT-FOR-US: Vade Secure Gateway
-CVE-2023-29711
-	RESERVED
+CVE-2023-29711 (An incorrect access control issue was discovered in Interlink PSG-5124 ...)
+	TODO: check
 CVE-2023-29710
 	RESERVED
-CVE-2023-29709
-	RESERVED
-CVE-2023-29708
-	RESERVED
-CVE-2023-29707
-	RESERVED
+CVE-2023-29709 (An issue was discovered in /cgi-bin/login_rj.cgi in Wildix WSG24POE ve ...)
+	TODO: check
+CVE-2023-29708 (An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter versi ...)
+	TODO: check
+CVE-2023-29707 (Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Cent ...)
+	TODO: check
 CVE-2023-29706
 	RESERVED
 CVE-2023-29705
@@ -12152,10 +12250,10 @@ CVE-2023-28802
 	RESERVED
 CVE-2023-28801
 	RESERVED
-CVE-2023-28800
-	RESERVED
-CVE-2023-28799
-	RESERVED
+CVE-2023-28800 (When using local accounts for administration, the redirect url paramet ...)
+	TODO: check
+CVE-2023-28799 (A URL parameter during login flow was vulnerable to injection. An atta ...)
+	TODO: check
 CVE-2023-28798
 	RESERVED
 CVE-2023-28797
@@ -12184,8 +12282,8 @@ CVE-2023-28786
 	RESERVED
 CVE-2023-28785 (Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability i ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2023-28784
-	RESERVED
+CVE-2023-28784 (Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contest  ...)
+	TODO: check
 CVE-2023-28783
 	RESERVED
 CVE-2023-28782
@@ -12196,16 +12294,16 @@ CVE-2023-28780
 	RESERVED
 CVE-2023-28779
 	RESERVED
-CVE-2023-28778
-	RESERVED
+CVE-2023-28778 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Best ...)
+	TODO: check
 CVE-2023-28777
 	RESERVED
-CVE-2023-28776
-	RESERVED
+CVE-2023-28776 (Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirte ...)
+	TODO: check
 CVE-2023-28775
 	RESERVED
-CVE-2023-28774
-	RESERVED
+CVE-2023-28774 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Grad ...)
+	TODO: check
 CVE-2023-28773
 	RESERVED
 CVE-2023-28772 (An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf ...)
@@ -12367,8 +12465,8 @@ CVE-2023-1584
 	NOT-FOR-US: Quarkus
 CVE-2023-28751
 	RESERVED
-CVE-2023-28750
-	RESERVED
+CVE-2023-28750 (Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio  ...)
+	TODO: check
 CVE-2023-28749
 	RESERVED
 CVE-2023-28748
@@ -12561,8 +12659,8 @@ CVE-2023-28697 (Moxa MiiNePort E1 has a vulnerability of insufficient access con
 	NOT-FOR-US: Moxa
 CVE-2023-28696
 	RESERVED
-CVE-2023-28695
-	RESERVED
+CVE-2023-28695 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Drew ...)
+	TODO: check
 CVE-2023-28694
 	RESERVED
 CVE-2023-28693
@@ -13110,8 +13208,8 @@ CVE-2023-28536
 	RESERVED
 CVE-2023-28535
 	RESERVED
-CVE-2023-28534
-	RESERVED
+CVE-2023-28534 (Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in ...)
+	TODO: check
 CVE-2023-28533
 	RESERVED
 CVE-2023-28532
@@ -13189,8 +13287,8 @@ CVE-2023-28498
 	RESERVED
 CVE-2023-28497
 	RESERVED
-CVE-2023-28496
-	RESERVED
+CVE-2023-28496 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SMTP ...)
+	TODO: check
 CVE-2023-28495
 	RESERVED
 CVE-2023-28494
@@ -13554,8 +13652,8 @@ CVE-2023-28425 (Redis is an in-memory database that persists on disk. Starting i
 	NOTE: https://github.com/redis/redis/security/advisories/GHSA-mvmm-4vq6-vw8c
 CVE-2023-28424 (Soko if the code that powers packages.gentoo.org. Prior to version 1.0 ...)
 	NOT-FOR-US: Soko
-CVE-2023-28423
-	RESERVED
+CVE-2023-28423 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pris ...)
+	TODO: check
 CVE-2023-28422 (Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Mage ...)
 	NOT-FOR-US: WooCommerce plugin
 CVE-2023-28421
@@ -13564,8 +13662,8 @@ CVE-2023-28420
 	RESERVED
 CVE-2023-28419
 	RESERVED
-CVE-2023-28418
-	RESERVED
+CVE-2023-28418 (Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability ...)
+	TODO: check
 CVE-2023-28417
 	RESERVED
 CVE-2023-28416
@@ -14380,8 +14478,8 @@ CVE-2023-28176 (Memory safety bugs present in Firefox 110 and Firefox ESR 102.8.
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-11/#CVE-2023-28176
 CVE-2023-28175 (Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11 ...)
 	NOT-FOR-US: Bosch
-CVE-2023-28174
-	RESERVED
+CVE-2023-28174 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in eLig ...)
+	TODO: check
 CVE-2023-28173
 	RESERVED
 CVE-2023-28172
@@ -14396,8 +14494,8 @@ CVE-2023-28168
 	RESERVED
 CVE-2023-28167
 	RESERVED
-CVE-2023-28166
-	RESERVED
+CVE-2023-28166 (Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aakif Ka ...)
+	TODO: check
 CVE-2023-28165
 	RESERVED
 CVE-2023-28164 (Dragging a URL from a cross-origin iframe that was removed during the  ...)
@@ -16203,8 +16301,8 @@ CVE-2023-27620 (Auth. (contributor+) Stored Cross-site Scripting (XSS) vulnerabi
 	NOT-FOR-US: WordPress plugin
 CVE-2023-27619 (Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability  ...)
 	NOT-FOR-US: WordPress theme
-CVE-2023-27618
-	RESERVED
+CVE-2023-27618 (Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in AGI ...)
+	TODO: check
 CVE-2023-27617
 	RESERVED
 CVE-2023-27616
@@ -16766,8 +16864,8 @@ CVE-2023-27454
 	RESERVED
 CVE-2023-27453
 	RESERVED
-CVE-2023-27452
-	RESERVED
+CVE-2023-27452 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow- ...)
+	TODO: check
 CVE-2023-27451
 	RESERVED
 CVE-2023-27450 (Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa of ...)
@@ -17774,8 +17872,8 @@ CVE-2023-27085
 	RESERVED
 CVE-2023-27084 (Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allo ...)
 	NOT-FOR-US: Dreamer CMS
-CVE-2023-27083
-	RESERVED
+CVE-2023-27083 (An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-d ...)
+	TODO: check
 CVE-2023-27082
 	RESERVED
 CVE-2023-27081
@@ -19016,8 +19114,8 @@ CVE-2023-26541 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability i
 	TODO: check
 CVE-2023-26540
 	RESERVED
-CVE-2023-26539
-	RESERVED
+CVE-2023-26539 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max  ...)
+	TODO: check
 CVE-2023-26538 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kamy ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2023-26537 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nico ...)
@@ -19026,8 +19124,8 @@ CVE-2023-26536 (Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in
 	NOT-FOR-US: WordPress plugin
 CVE-2023-26535
 	RESERVED
-CVE-2023-26534
-	RESERVED
+CVE-2023-26534 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in OneW ...)
+	TODO: check
 CVE-2023-26533
 	RESERVED
 CVE-2023-26532
@@ -22364,10 +22462,10 @@ CVE-2023-25502
 	RESERVED
 CVE-2023-25501
 	RESERVED
-CVE-2023-25500
-	RESERVED
-CVE-2023-25499
-	RESERVED
+CVE-2023-25500 (Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to ...)
+	TODO: check
+CVE-2023-25499 (When adding non-visible components to the UI in server side, content i ...)
+	TODO: check
 CVE-2023-24019
 	RESERVED
 CVE-2023-0705 (Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allow ...)
@@ -27112,16 +27210,16 @@ CVE-2023-23813 (Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dols
 	NOT-FOR-US: WordPress plugin
 CVE-2023-23812 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joos ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2023-23811
-	RESERVED
+CVE-2023-23811 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Neil ...)
+	TODO: check
 CVE-2023-23810 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2023-23809 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mori ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2023-23808 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Serg ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2023-23807
-	RESERVED
+CVE-2023-23807 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Qumo ...)
+	TODO: check
 CVE-2023-23806 (Auth. (admin+) StoredCross-Site Scripting (XSS) vulnerability in Davin ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2023-23805
@@ -27144,8 +27242,8 @@ CVE-2023-23797 (Cross-Site Request Forgery (CSRF) vulnerability in SecondLineThe
 	NOT-FOR-US: WordPress plugin
 CVE-2023-23796
 	RESERVED
-CVE-2023-23795
-	RESERVED
+CVE-2023-23795 (Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Form Builder ...)
+	TODO: check
 CVE-2023-23794 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2023-23793 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eigh ...)
@@ -34158,8 +34256,8 @@ CVE-2022-47595 (Improper Limitation of a Pathname to a Restricted Directory ('Pa
 	NOT-FOR-US: WordPress plugin
 CVE-2022-47594
 	RESERVED
-CVE-2022-47593
-	RESERVED
+CVE-2022-47593 (Auth. (subscriber+) SQL Injection (SQLi) vulnerability in RapidLoad Ra ...)
+	TODO: check
 CVE-2022-47592 (Reflected Cross-Site Scripting (XSS) vulnerability in Dmytriy.Cooperma ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-47591 (Reflected Cross-Site Scripting (XSS) vulnerability in Mickael Austoni  ...)
@@ -45560,16 +45658,16 @@ CVE-2023-20898
 	RESERVED
 CVE-2023-20897
 	RESERVED
-CVE-2023-20896
-	RESERVED
-CVE-2023-20895
-	RESERVED
-CVE-2023-20894
-	RESERVED
-CVE-2023-20893
-	RESERVED
-CVE-2023-20892
-	RESERVED
+CVE-2023-20896 (The VMware vCenter Server contains an out-of-bounds read vulnerability ...)
+	TODO: check
+CVE-2023-20895 (The VMware vCenter Server contains a memory corruption vulnerability i ...)
+	TODO: check
+CVE-2023-20894 (The VMware vCenter Server contains an out-of-bounds write vulnerabilit ...)
+	TODO: check
+CVE-2023-20893 (The VMware vCenter Server contains a use-after-free vulnerability in t ...)
+	TODO: check
+CVE-2023-20892 (The vCenter Server contains a heap overflow vulnerability due to the u ...)
+	TODO: check
 CVE-2023-20891
 	RESERVED
 CVE-2023-20890
@@ -115887,7 +115985,7 @@ CVE-2022-21948 (An Improper Neutralization of Input During Web Page Generation (
 	NOT-FOR-US: OpenSuSE paste
 CVE-2022-21947 (A Improper Access Control vulnerability in Rancher Desktop of SUSE all ...)
 	NOT-FOR-US: Rancher
-CVE-2022-21946 (A Improper Privilege Management vulnerability in the sudoers configura ...)
+CVE-2022-21946 (A Incorrect Permission Assignment for Critical Resource vulnerability  ...)
 	NOT-FOR-US: SUSE cscreen
 CVE-2022-21945 (A Insecure Temporary File vulnerability in cscreen of openSUSE Factory ...)
 	NOT-FOR-US: SUSE cscreen
@@ -171446,7 +171544,7 @@ CVE-2021-25317 (A Incorrect Default Permissions vulnerability in the packaging o
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1949119
 CVE-2021-25316 (A Insecure Temporary File vulnerability in s390-tools of SUSE Linux En ...)
 	NOT-FOR-US: SuSE (different from src:s390-tools in Debian)
-CVE-2021-25315 (A Incorrect Implementation of Authentication Algorithm vulnerability i ...)
+CVE-2021-25315 (CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Ent ...)
 	- salt <not-affected> (SuSE specific issue, cf #985085)
 	NOTE: https://bugzilla.suse.com/show_bug.cgi?id=1182382
 CVE-2021-25314 (A Creation of Temporary File With Insecure Permissions vulnerability i ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e0a3ba0aa14ecaeed00bdf80de318fa71a192f45

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e0a3ba0aa14ecaeed00bdf80de318fa71a192f45
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230622/7faa5fd6/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list