[Git][security-tracker-team/security-tracker][master] new gitlab issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Mar 10 11:04:45 GMT 2023
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ea71b6bd by Moritz Muehlenhoff at 2023-03-10T12:03:52+01:00
new gitlab issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2105,7 +2105,7 @@ CVE-2023-1086
CVE-2023-1085
RESERVED
CVE-2023-1084 (An issue has been discovered in GitLab CE/EE affecting all versions be ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2023-1083
RESERVED
CVE-2023-1082
@@ -2239,7 +2239,7 @@ CVE-2023-1073
NOTE: https://git.kernel.org/linus/b12fece4c64857e5fab4290bf01b2e0317a88456
NOTE: https://www.openwall.com/lists/oss-security/2023/01/17/3
CVE-2023-1072 (An issue has been discovered in GitLab affecting all versions starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2023-1071
RESERVED
CVE-2023-1070 (External Control of File Name or Path in GitHub repository nilsteampas ...)
@@ -9812,7 +9812,7 @@ CVE-2023-0485
CVE-2023-0484
RESERVED
CVE-2023-0483 (An issue has been discovered in GitLab affecting all versions starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2023-0482 (In RESTEasy the insecure File.createTempFile() is used in the DataSour ...)
- resteasy <unfixed> (bug #1031728)
- resteasy3.0 <unfixed> (bug #1031729)
@@ -13128,7 +13128,7 @@ CVE-2023-0225
CVE-2023-0224
RESERVED
CVE-2023-0223 (An issue has been discovered in GitLab affecting all versions starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-4886
RESERVED
CVE-2022-48255 (There is a system command injection vulnerability in BiSheng-WNM FW 3. ...)
@@ -15524,7 +15524,7 @@ CVE-2023-0051 (Heap-based Buffer Overflow in GitHub repository vim/vim prior to
NOTE: https://github.com/vim/vim/commit/c32949b0779106ed5710ae3bffc5053e49083ab4 (v9.0.1144)
NOTE: Crash in CLI tool, no security impact
CVE-2023-0050 (An issue has been discovered in GitLab affecting all versions starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2023-0049 (Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. ...)
- vim 2:9.0.1378-1 (unimportant)
NOTE: https://huntr.dev/bounties/5e6f325c-ba54-4bf0-b050-dca048fd3fd9
@@ -20294,7 +20294,7 @@ CVE-2022-4464 (Themify Portfolio Post WordPress plugin before 1.2.1 does not val
CVE-2022-4463
RESERVED
CVE-2022-4462 (An issue has been discovered in GitLab affecting all versions starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-4461
RESERVED
CVE-2022-4460 (The Sidebar Widgets by CodeLights WordPress plugin through 1.4 does no ...)
@@ -22097,7 +22097,7 @@ CVE-2022-4333
CVE-2022-4332
RESERVED
CVE-2022-4331 (An issue has been discovered in GitLab EE affecting all versions start ...)
- TODO: check
+ - gitlab <not-affected> (Specific to EE)
CVE-2022-4330 (The WP Attachments WordPress plugin through 5.0.5 does not sanitise an ...)
NOT-FOR-US: WordPress plugin
CVE-2022-4329 (The Product list Widget for Woocommerce WordPress plugin through 1.0 d ...)
@@ -22391,11 +22391,11 @@ CVE-2022-4318
RESERVED
- cri-o <itp> (bug #979702)
CVE-2022-4317 (An issue has been discovered in GitLab DAST analyzer affecting all ver ...)
- TODO: check
+ NOT-FOR-US: Gitlab DAST analyzer
CVE-2022-4316
RESERVED
CVE-2022-4315 (An issue has been discovered in GitLab DAST analyzer affecting all ver ...)
- TODO: check
+ NOT-FOR-US: Gitlab DAST analyzer
CVE-2022-4314 (Improper Privilege Management in GitHub repository ikus060/rdiffweb pr ...)
- rdiffweb <itp> (bug #969974)
CVE-2022-4313
@@ -22988,7 +22988,7 @@ CVE-2022-4291 (The aswjsflt.dll library from Avast Antivirus windows contained a
CVE-2022-4290
RESERVED
CVE-2022-4289 (An issue has been discovered in GitLab affecting all versions starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-4288
RESERVED
CVE-2022-4287 (Authentication bypass in local application lock feature in Devolutions ...)
@@ -25981,7 +25981,7 @@ CVE-2022-4009
CVE-2022-4008
RESERVED
CVE-2022-4007 (A issue has been discovered in GitLab CE/EE affecting all versions fro ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-4006 (A vulnerability, which was classified as problematic, has been found i ...)
NOT-FOR-US: WBCE CMS
CVE-2022-4005 (The Donation Button WordPress plugin through 4.0.0 does not sanitize a ...)
@@ -30184,7 +30184,7 @@ CVE-2022-3760 (Improper Neutralization of Special Elements used in an SQL Comman
CVE-2022-3759 (An issue has been discovered in GitLab CE/EE affecting all versions st ...)
- gitlab <unfixed>
CVE-2022-3758 (An issue has been discovered in GitLab affecting all versions starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-44418
RESERVED
CVE-2022-44417
@@ -38837,7 +38837,7 @@ CVE-2022-41617 (In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1
CVE-2022-36795 (In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15. ...)
NOT-FOR-US: F5 BIG-IP
CVE-2022-3381 (An issue has been discovered in GitLab affecting all versions starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-3380 (The Customizer Export/Import WordPress plugin before 0.9.5 unserialize ...)
NOT-FOR-US: WordPress plugin
CVE-2022-3379 (Horner Automation's Cscape version 9.90 SP7 and prior does not properl ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea71b6bda0a2606cb7d04a39f512f30187394fb8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea71b6bda0a2606cb7d04a39f512f30187394fb8
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230310/d14bd2ca/attachment.htm>
More information about the debian-security-tracker-commits
mailing list