[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Jun 27 09:02:58 BST 2023
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b2c20f06 by Moritz Muehlenhoff at 2023-06-27T10:02:35+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,5 @@
+CVE-2023-3361
+ NOT-FOR-US: OpenShift Data
CVE-2023-3422
- chromium <unfixed>
[buster] - chromium <end-of-life> (see DSA 5046)
@@ -10,7 +12,7 @@ CVE-2023-3420
CVE-2023-3398 (Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.)
NOT-FOR-US: jgraph/drawio
CVE-2023-3113 (An unauthenticated XML external entity injection (XXE) vulnerability e ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2023-36631 (Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Fir ...)
NOT-FOR-US: Malwarebytes Binisoft Windows Firewall Control
CVE-2023-36301 (Talend Data Catalog before 8.0-20230221 contain a directory traversal ...)
@@ -18,29 +20,29 @@ CVE-2023-36301 (Talend Data Catalog before 8.0-20230221 contain a directory trav
CVE-2023-36252 (An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote ...)
NOT-FOR-US: Ateme Flamingo XL
CVE-2023-35933 (OPenFGA is an open source authorization/permission engine built for de ...)
- TODO: check
+ NOT-FOR-US: OPenFGA
CVE-2023-35930 (SpiceDB is an open source, Google Zanzibar-inspired, database system f ...)
- TODO: check
+ NOT-FOR-US: SpiceDB
CVE-2023-35170 (Sliver is an open source cross-platform adversary emulation/red team f ...)
- TODO: check
+ NOT-FOR-US: Sliver
CVE-2023-34422 (A valid, authenticated LXCA user with elevated privileges may be able ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2023-34421 (A valid, authenticated LXCA user with elevated privileges may be able ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2023-34420 (A valid, authenticated LXCA user with elevated privileges may be able ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2023-34418 (A valid, authenticated LXCA user may be able to gain unauthorized acce ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2023-33580 (Phpgurukul Student Study Center Management System V1.0 is vulnerable t ...)
NOT-FOR-US: Phpgurukul Student Study Center Management System
CVE-2023-33404 (An Unrestricted Upload vulnerability, due to insufficient validation o ...)
- TODO: check
+ NOT-FOR-US: BlogEngine.Net
CVE-2023-33176 (BigBlueButton is an open source virtual classroom designed to help tea ...)
NOT-FOR-US: BigBlueButton
CVE-2023-2993 (A valid, authenticated user with limited privileges may be able to use ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2023-2992 (An unauthenticated denial of service vulnerability exists in the SMM v ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2023-36675 (An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1. ...)
- mediawiki <unfixed>
NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/921452
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2c20f0641daaf88fc25b3ba78bd09e2d92f02c9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2c20f0641daaf88fc25b3ba78bd09e2d92f02c9
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230627/2cf448b1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list