[Git][security-tracker-team/security-tracker][master] Track some CVEs for mattermost, itp'ed

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 22 09:22:08 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f535b6e3 by Salvatore Bonaccorso at 2024-08-22T10:21:40+02:00
Track some CVEs for mattermost, itp'ed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2024-8072 (Mage AI allows remote unauthenticated attackers to leak the terminal s ...)
 	NOT-FOR-US: Mage AI
 CVE-2024-8071 (Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2024-7836 (The Themify Builder plugin for WordPress is vulnerable to unauthorized ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-7384 (The AcyMailing \u2013 An Ultimate Newsletter Plugin and Marketing Auto ...)
@@ -23,23 +23,23 @@ CVE-2024-45165 (An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) thr
 CVE-2024-45163 (The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connec ...)
 	TODO: check
 CVE-2024-43813 (Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce p ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2024-43033 (JPress through 5.1.1 on Windows has an arbitrary file upload vulnerabi ...)
 	NOT-FOR-US: JPress
 CVE-2024-42411 (Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0,  ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2024-42056 (Retool (self-hosted enterprise) through 3.40.0 inserts resource authen ...)
 	TODO: check
 CVE-2024-40886 (Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0,  ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2024-39836 (Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2024-39810 (Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time l ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2024-39576 (Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incor ...)
 	NOT-FOR-US: Dell
 CVE-2024-32939 (Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0,  ...)
-	TODO: check
+	- mattermost-server <itp> (bug #823556)
 CVE-2024-28987 (The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded ...)
 	NOT-FOR-US: SolarWinds
 CVE-2022-48943 (In the Linux kernel, the following vulnerability has been resolved:  K ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f535b6e32aff42036f0aa18ac3580e8e7f8d6490

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f535b6e32aff42036f0aa18ac3580e8e7f8d6490
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240822/944d3990/attachment.htm>


More information about the debian-security-tracker-commits mailing list