[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Oct 18 10:28:50 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0d1b00d6 by Salvatore Bonaccorso at 2023-10-18T11:28:15+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,11 +3,11 @@ CVE-2023-5626 (Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs pr
 CVE-2023-5621 (The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable  ...)
 	NOT-FOR-US: Thumbnail Slider With Lightbox plugin for WordPress
 CVE-2023-5552 (A password disclosure vulnerability in the Secure PDF eXchange (SPX) f ...)
-	TODO: check
+	NOT-FOR-US: Sophos
 CVE-2023-5538 (The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross ...)
 	NOT-FOR-US: MpOperationLogs plugin for WordPress
 CVE-2023-4938 (The BEAR for WordPress is vulnerable to Missing Authorization in versi ...)
-	TODO: check
+	NOT-FOR-US: BEAR for WordPress
 CVE-2023-45811 (Synchrony deobfuscator is a javascript cleaner & deobfuscator.  A `__p ...)
 	TODO: check
 CVE-2023-45810 (OpenFGA is a flexible authorization/permission engine built for develo ...)
@@ -65,29 +65,29 @@ CVE-2023-35084 (Unsafe Deserialization of User Input could lead to Execution of
 CVE-2023-35083 (Allows an authenticated attacker with network access to read arbitrary ...)
 	TODO: check
 CVE-2023-5522 (Mattermost Mobile fails to limitthe maximum number of Markdown element ...)
-	TODO: check
+	NOT-FOR-US: Mattermost Mobile
 CVE-2023-5339 (Mattermost Desktopfails to set an appropriate log level during initial ...)
-	TODO: check
+	NOT-FOR-US: Mattermost Desktop
 CVE-2023-4896 (A vulnerability exists which allows an authenticated attacker to acces ...)
-	TODO: check
+	NOT-FOR-US: Aruba Networks
 CVE-2023-45952 (An arbitrary file upload vulnerability in the component ajax_link.php  ...)
-	TODO: check
+	NOT-FOR-US: lylme_spage
 CVE-2023-45951 (lylme_spage v1.7.0 was discovered to contain a SQL injection vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: lylme_spage
 CVE-2023-45907 (Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forg ...)
-	TODO: check
+	NOT-FOR-US: Dreamer CMS
 CVE-2023-45906 (Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forg ...)
-	TODO: check
+	NOT-FOR-US: Dreamer CMS
 CVE-2023-45905 (Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forg ...)
-	TODO: check
+	NOT-FOR-US: Dreamer CMS
 CVE-2023-45904 (Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forg ...)
-	TODO: check
+	NOT-FOR-US: Dreamer CMS
 CVE-2023-45903 (Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forg ...)
-	TODO: check
+	NOT-FOR-US: Dreamer CMS
 CVE-2023-45902 (Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forg ...)
-	TODO: check
+	NOT-FOR-US: Dreamer CMS
 CVE-2023-45901 (Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forg ...)
-	TODO: check
+	NOT-FOR-US: Dreamer CMS
 CVE-2023-45803 (urllib3 is a user-friendly HTTP client library for Python. urllib3 pre ...)
 	TODO: check
 CVE-2023-45010 (Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d1b00d6e013f961f8db522d7c529fd4c2f639e7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d1b00d6e013f961f8db522d7c529fd4c2f639e7
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231018/39be9fb5/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list