[Git][security-tracker-team/security-tracker][master] new gitlab issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Mar 10 11:04:45 GMT 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ea71b6bd by Moritz Muehlenhoff at 2023-03-10T12:03:52+01:00
new gitlab issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2105,7 +2105,7 @@ CVE-2023-1086
 CVE-2023-1085
 	RESERVED
 CVE-2023-1084 (An issue has been discovered in GitLab CE/EE affecting all versions be ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2023-1083
 	RESERVED
 CVE-2023-1082
@@ -2239,7 +2239,7 @@ CVE-2023-1073
 	NOTE: https://git.kernel.org/linus/b12fece4c64857e5fab4290bf01b2e0317a88456
 	NOTE: https://www.openwall.com/lists/oss-security/2023/01/17/3
 CVE-2023-1072 (An issue has been discovered in GitLab affecting all versions starting ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2023-1071
 	RESERVED
 CVE-2023-1070 (External Control of File Name or Path in GitHub repository nilsteampas ...)
@@ -9812,7 +9812,7 @@ CVE-2023-0485
 CVE-2023-0484
 	RESERVED
 CVE-2023-0483 (An issue has been discovered in GitLab affecting all versions starting ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2023-0482 (In RESTEasy the insecure File.createTempFile() is used in the DataSour ...)
 	- resteasy <unfixed> (bug #1031728)
 	- resteasy3.0 <unfixed> (bug #1031729)
@@ -13128,7 +13128,7 @@ CVE-2023-0225
 CVE-2023-0224
 	RESERVED
 CVE-2023-0223 (An issue has been discovered in GitLab affecting all versions starting ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2022-4886
 	RESERVED
 CVE-2022-48255 (There is a system command injection vulnerability in BiSheng-WNM FW 3. ...)
@@ -15524,7 +15524,7 @@ CVE-2023-0051 (Heap-based Buffer Overflow in GitHub repository vim/vim prior to
 	NOTE: https://github.com/vim/vim/commit/c32949b0779106ed5710ae3bffc5053e49083ab4 (v9.0.1144)
 	NOTE: Crash in CLI tool, no security impact
 CVE-2023-0050 (An issue has been discovered in GitLab affecting all versions starting ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2023-0049 (Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. ...)
 	- vim 2:9.0.1378-1 (unimportant)
 	NOTE: https://huntr.dev/bounties/5e6f325c-ba54-4bf0-b050-dca048fd3fd9
@@ -20294,7 +20294,7 @@ CVE-2022-4464 (Themify Portfolio Post WordPress plugin before 1.2.1 does not val
 CVE-2022-4463
 	RESERVED
 CVE-2022-4462 (An issue has been discovered in GitLab affecting all versions starting ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2022-4461
 	RESERVED
 CVE-2022-4460 (The Sidebar Widgets by CodeLights WordPress plugin through 1.4 does no ...)
@@ -22097,7 +22097,7 @@ CVE-2022-4333
 CVE-2022-4332
 	RESERVED
 CVE-2022-4331 (An issue has been discovered in GitLab EE affecting all versions start ...)
-	TODO: check
+	- gitlab <not-affected> (Specific to EE)
 CVE-2022-4330 (The WP Attachments WordPress plugin through 5.0.5 does not sanitise an ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-4329 (The Product list Widget for Woocommerce WordPress plugin through 1.0 d ...)
@@ -22391,11 +22391,11 @@ CVE-2022-4318
 	RESERVED
 	- cri-o <itp> (bug #979702)
 CVE-2022-4317 (An issue has been discovered in GitLab DAST analyzer affecting all ver ...)
-	TODO: check
+	NOT-FOR-US: Gitlab DAST analyzer
 CVE-2022-4316
 	RESERVED
 CVE-2022-4315 (An issue has been discovered in GitLab DAST analyzer affecting all ver ...)
-	TODO: check
+	NOT-FOR-US: Gitlab DAST analyzer
 CVE-2022-4314 (Improper Privilege Management in GitHub repository ikus060/rdiffweb pr ...)
 	- rdiffweb <itp> (bug #969974)
 CVE-2022-4313
@@ -22988,7 +22988,7 @@ CVE-2022-4291 (The aswjsflt.dll library from Avast Antivirus windows contained a
 CVE-2022-4290
 	RESERVED
 CVE-2022-4289 (An issue has been discovered in GitLab affecting all versions starting ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2022-4288
 	RESERVED
 CVE-2022-4287 (Authentication bypass in local application lock feature in Devolutions ...)
@@ -25981,7 +25981,7 @@ CVE-2022-4009
 CVE-2022-4008
 	RESERVED
 CVE-2022-4007 (A issue has been discovered in GitLab CE/EE affecting all versions fro ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2022-4006 (A vulnerability, which was classified as problematic, has been found i ...)
 	NOT-FOR-US: WBCE CMS
 CVE-2022-4005 (The Donation Button WordPress plugin through 4.0.0 does not sanitize a ...)
@@ -30184,7 +30184,7 @@ CVE-2022-3760 (Improper Neutralization of Special Elements used in an SQL Comman
 CVE-2022-3759 (An issue has been discovered in GitLab CE/EE affecting all versions st ...)
 	- gitlab <unfixed>
 CVE-2022-3758 (An issue has been discovered in GitLab affecting all versions starting ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2022-44418
 	RESERVED
 CVE-2022-44417
@@ -38837,7 +38837,7 @@ CVE-2022-41617 (In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1
 CVE-2022-36795 (In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15. ...)
 	NOT-FOR-US: F5 BIG-IP
 CVE-2022-3381 (An issue has been discovered in GitLab affecting all versions starting ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2022-3380 (The Customizer Export/Import WordPress plugin before 0.9.5 unserialize ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2022-3379 (Horner Automation's Cscape version 9.90 SP7 and prior does not properl ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea71b6bda0a2606cb7d04a39f512f30187394fb8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea71b6bda0a2606cb7d04a39f512f30187394fb8
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230310/d14bd2ca/attachment.htm>


More information about the debian-security-tracker-commits mailing list