[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Apr 9 21:18:16 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
96765a2a by Salvatore Bonaccorso at 2024-04-09T22:17:24+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -45,11 +45,11 @@ CVE-2024-31866 (Improper Encoding or Escaping of Output vulnerability in Apache
 CVE-2024-31865 (Improper Input Validation vulnerability in Apache Zeppelin.  The attac ...)
 	NOT-FOR-US: Apache Zeppelin
 CVE-2024-31864 (Improper Control of Generation of Code ('Code Injection') vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: Apache Zeppelin
 CVE-2024-31863 (Authentication Bypass by Spoofing vulnerability by replacing to exsiti ...)
-	TODO: check
+	NOT-FOR-US: Apache Zeppelin
 CVE-2024-31862 (Improper Input Validation vulnerability in Apache Zeppelin when creati ...)
-	TODO: check
+	NOT-FOR-US: Apache Zeppelin
 CVE-2024-31860 (Improper Input Validation vulnerability in Apache Zeppelin.  By adding ...)
 	TODO: check
 CVE-2024-31544 (A stored cross-site scripting (XSS) vulnerability in Computer Laborato ...)
@@ -219364,7 +219364,7 @@ CVE-2021-28657 (A carefully crafted or corrupt file may trigger an infinite loop
 	[buster] - tika <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2021/03/30/3
 CVE-2021-28656 (Cross-Site Request Forgery (CSRF) vulnerability in Credential page of  ...)
-	TODO: check
+	NOT-FOR-US: Apache Zeppelin
 CVE-2021-28655 (The improper Input Validation vulnerability in "\u201dMove folder to T ...)
 	NOT-FOR-US: Apache Zeppelin
 CVE-2021-28654



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/96765a2a7d40a546001c891010a7d0d44a82d32e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/96765a2a7d40a546001c891010a7d0d44a82d32e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240409/2fd53b7b/attachment.htm>


More information about the debian-security-tracker-commits mailing list