[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Apr 18 07:31:15 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
de741f76 by Salvatore Bonaccorso at 2024-04-18T08:30:39+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -220,9 +220,9 @@ CVE-2024-21989 (ONTAP Select Deploy administration utility versions 9.12.1.x,  9
 CVE-2024-1350 (Missing Authorization vulnerability in Prasidhda Malla Honeypot for WP ...)
 	TODO: check
 CVE-2024-1249 (A flaw was found in Keycloak's OIDC component in the "checkLoginIframe ...)
-	TODO: check
+	NOT-FOR-US: Keycloak
 CVE-2024-1132 (A flaw was found in Keycloak, where it does not properly validate URLs ...)
-	TODO: check
+	NOT-FOR-US: Keycloak
 CVE-2024-0257 (RoboDK v5.5.4   is vulnerable to heap-based buffer overflow while proc ...)
 	TODO: check
 CVE-2023-6805 (The RSS Aggregator by Feedzy \u2013 Feed to Post, Autoblogging, News & ...)
@@ -82366,8 +82366,13 @@ CVE-2023-25020 (Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Kibok
 	NOT-FOR-US: WordPress plugin
 CVE-2023-25019 (Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premio C ...)
 	NOT-FOR-US: WordPress plugin
+CVE-2023-6717
+	NOT-FOR-US: Keycloak
+CVE-2023-6544
+	NOT-FOR-US: Keycloak
 CVE-2023-0657
 	RESERVED
+	NOT-FOR-US: Keycloak
 CVE-2023-0656 (A Stack-based buffer overflow vulnerability in the SonicOS allows a re ...)
 	NOT-FOR-US: SonicOS
 CVE-2023-0655 (SonicWall Email Security contains a vulnerability that could permit a  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de741f764659165c2376dce4e9d11025e9faf7c6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de741f764659165c2376dce4e9d11025e9faf7c6
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240418/b7b65da8/attachment.htm>


More information about the debian-security-tracker-commits mailing list