[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Jun 27 09:02:58 BST 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b2c20f06 by Moritz Muehlenhoff at 2023-06-27T10:02:35+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,5 @@
+CVE-2023-3361
+	NOT-FOR-US: OpenShift Data
 CVE-2023-3422
 	- chromium <unfixed>
 	[buster] - chromium <end-of-life> (see DSA 5046)
@@ -10,7 +12,7 @@ CVE-2023-3420
 CVE-2023-3398 (Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.)
 	NOT-FOR-US: jgraph/drawio
 CVE-2023-3113 (An unauthenticated XML external entity injection (XXE) vulnerability e ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2023-36631 (Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Fir ...)
 	NOT-FOR-US: Malwarebytes Binisoft Windows Firewall Control
 CVE-2023-36301 (Talend Data Catalog before 8.0-20230221 contain a directory traversal  ...)
@@ -18,29 +20,29 @@ CVE-2023-36301 (Talend Data Catalog before 8.0-20230221 contain a directory trav
 CVE-2023-36252 (An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote  ...)
 	NOT-FOR-US: Ateme Flamingo XL
 CVE-2023-35933 (OPenFGA is an open source authorization/permission engine built for de ...)
-	TODO: check
+	NOT-FOR-US: OPenFGA
 CVE-2023-35930 (SpiceDB is an open source, Google Zanzibar-inspired, database system f ...)
-	TODO: check
+	NOT-FOR-US: SpiceDB
 CVE-2023-35170 (Sliver is an open source cross-platform adversary emulation/red team f ...)
-	TODO: check
+	NOT-FOR-US: Sliver
 CVE-2023-34422 (A valid, authenticated LXCA user with elevated privileges may be able  ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2023-34421 (A valid, authenticated LXCA user with elevated privileges may be able  ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2023-34420 (A valid, authenticated LXCA user with elevated privileges may be able  ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2023-34418 (A valid, authenticated LXCA user may be able to gain unauthorized acce ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2023-33580 (Phpgurukul Student Study Center Management System V1.0 is vulnerable t ...)
 	NOT-FOR-US: Phpgurukul Student Study Center Management System
 CVE-2023-33404 (An Unrestricted Upload vulnerability, due to insufficient validation o ...)
-	TODO: check
+	NOT-FOR-US: BlogEngine.Net
 CVE-2023-33176 (BigBlueButton is an open source virtual classroom designed to help tea ...)
 	NOT-FOR-US: BigBlueButton
 CVE-2023-2993 (A valid, authenticated user with limited privileges may be able to use ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2023-2992 (An unauthenticated denial of service vulnerability exists in the SMM v ...)
-	TODO: check
+	NOT-FOR-US: Lenovo
 CVE-2023-36675 (An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1. ...)
 	- mediawiki <unfixed>
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/921452



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2c20f0641daaf88fc25b3ba78bd09e2d92f02c9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2c20f0641daaf88fc25b3ba78bd09e2d92f02c9
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230627/2cf448b1/attachment.htm>


More information about the debian-security-tracker-commits mailing list