[Git][security-tracker-team/security-tracker][master] Process two more Mattermost CVEs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Nov 27 21:07:54 GMT 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
470b6a71 by Salvatore Bonaccorso at 2023-11-27T22:07:26+01:00
Process two more Mattermost CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -88,7 +88,7 @@ CVE-2023-47168 (Mattermost fails to properly check a redirect URL parameter allo
 CVE-2023-45223 (Mattermost fails to properly validate the "Show Full Name" option in a ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2023-43754 (Mattermost fails to check whether the \u201cAllow users to view archiv ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2023-42000 (Arcserve UDP prior to 9.2 contains a path traversal vulnerability in c ...)
 	NOT-FOR-US: Arcserve
 CVE-2023-41999 (An authentication bypass exists in Arcserve UDP prior to version 9.2.  ...)
@@ -108,7 +108,7 @@ CVE-2023-38573 (A use-after-free vulnerability exists in the way Foxit Reader 12
 CVE-2023-35985 (An arbitrary file creation vulnerability exists in the Javascript expo ...)
 	NOT-FOR-US: Foxit Reader
 CVE-2023-35075 (Mattermost fails to use innerText /textContentwhen setting the channel ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2023-32616 (A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.1 ...)
 	NOT-FOR-US: Foxit Reader
 CVE-2023-31275 (An uninitialized pointer use vulnerability exists in the functionality ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/470b6a71a69797c1a66957dbb0e3b8f5ccb469d7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/470b6a71a69797c1a66957dbb0e3b8f5ccb469d7
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231127/75386d65/attachment.htm>


More information about the debian-security-tracker-commits mailing list