[Git][security-tracker-team/security-tracker][master] Track some CVEs for mattermost, itp'ed
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 22 09:22:08 BST 2024
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f535b6e3 by Salvatore Bonaccorso at 2024-08-22T10:21:40+02:00
Track some CVEs for mattermost, itp'ed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
CVE-2024-8072 (Mage AI allows remote unauthenticated attackers to leak the terminal s ...)
NOT-FOR-US: Mage AI
CVE-2024-8071 (Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a ...)
- TODO: check
+ - mattermost-server <itp> (bug #823556)
CVE-2024-7836 (The Themify Builder plugin for WordPress is vulnerable to unauthorized ...)
NOT-FOR-US: WordPress plugin
CVE-2024-7384 (The AcyMailing \u2013 An Ultimate Newsletter Plugin and Marketing Auto ...)
@@ -23,23 +23,23 @@ CVE-2024-45165 (An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) thr
CVE-2024-45163 (The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connec ...)
TODO: check
CVE-2024-43813 (Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce p ...)
- TODO: check
+ - mattermost-server <itp> (bug #823556)
CVE-2024-43033 (JPress through 5.1.1 on Windows has an arbitrary file upload vulnerabi ...)
NOT-FOR-US: JPress
CVE-2024-42411 (Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...)
- TODO: check
+ - mattermost-server <itp> (bug #823556)
CVE-2024-42056 (Retool (self-hosted enterprise) through 3.40.0 inserts resource authen ...)
TODO: check
CVE-2024-40886 (Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...)
- TODO: check
+ - mattermost-server <itp> (bug #823556)
CVE-2024-39836 (Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a ...)
- TODO: check
+ - mattermost-server <itp> (bug #823556)
CVE-2024-39810 (Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time l ...)
- TODO: check
+ - mattermost-server <itp> (bug #823556)
CVE-2024-39576 (Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incor ...)
NOT-FOR-US: Dell
CVE-2024-32939 (Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, ...)
- TODO: check
+ - mattermost-server <itp> (bug #823556)
CVE-2024-28987 (The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded ...)
NOT-FOR-US: SolarWinds
CVE-2022-48943 (In the Linux kernel, the following vulnerability has been resolved: K ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f535b6e32aff42036f0aa18ac3580e8e7f8d6490
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f535b6e32aff42036f0aa18ac3580e8e7f8d6490
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240822/944d3990/attachment.htm>
More information about the debian-security-tracker-commits
mailing list