[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Dec 4 21:04:27 GMT 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a0f036be by Salvatore Bonaccorso at 2024-12-04T22:04:05+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,23 +1,23 @@
 CVE-2024-8962 (The WPBITS Addons For Elementor Page Builder plugin for WordPress is v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-8894 (Out-of-bounds Writevulnerability was discovered in Open Design Allianc ...)
-	TODO: check
+	NOT-FOR-US: Open Design Alliance Drawings SDK
 CVE-2024-7488 (Improper Input Validation vulnerability in RestApp Inc. Online Orderin ...)
-	TODO: check
+	NOT-FOR-US: RestApp Inc. Online Ordering System
 CVE-2024-5020 (Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-54158 (In JetBrains YouTrack before 2024.3.52635 potential spoofing attack wa ...)
-	TODO: check
+	NOT-FOR-US: JetBrains YouTrack
 CVE-2024-54157 (In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible ...)
-	TODO: check
+	NOT-FOR-US: JetBrains YouTrack
 CVE-2024-54156 (In JetBrains YouTrack before 2024.3.52635 multiple merge functions wer ...)
-	TODO: check
+	NOT-FOR-US: JetBrains YouTrack
 CVE-2024-54155 (In JetBrains YouTrack before 2024.3.51866 improper access control allo ...)
-	TODO: check
+	NOT-FOR-US: JetBrains YouTrack
 CVE-2024-54154 (In JetBrains YouTrack before 2024.3.51866 system takeover was possible ...)
-	TODO: check
+	NOT-FOR-US: JetBrains YouTrack
 CVE-2024-54153 (In JetBrains YouTrack before 2024.3.51866 unauthenticated database bac ...)
-	TODO: check
+	NOT-FOR-US: JetBrains YouTrack
 CVE-2024-54134 (A publish-access account was compromised for `@solana/web3.js`, a Java ...)
 	TODO: check
 CVE-2024-54132 (The GitHub CLI is GitHub\u2019s official command line tool. A security ...)
@@ -25,29 +25,29 @@ CVE-2024-54132 (The GitHub CLI is GitHub\u2019s official command line tool. A se
 CVE-2024-54002 (Dependency-Track is a Component Analysis platform that allows organiza ...)
 	TODO: check
 CVE-2024-53614 (A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attac ...)
-	TODO: check
+	NOT-FOR-US: Thinkware Cloud APK
 CVE-2024-52676 (Itsourcecode Online Discussion Forum Project v.1.0.0 is vulnerable to  ...)
-	TODO: check
+	NOT-FOR-US: Itsourcecode Online Discussion Forum Project
 CVE-2024-52278
 	REJECTED
 CVE-2024-52277 (User Interface (UI) Misrepresentation of Critical Information vulnerab ...)
-	TODO: check
+	NOT-FOR-US: DocuSeal
 CVE-2024-52276 (** INITIAL LIMITED RELEASE **  User Interface (UI) Misrepresentation o ...)
 	TODO: check
 CVE-2024-52275 (Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2024-52274 (Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2024-52273 (Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2024-52272 (Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2024-52269 (** INITIAL LIMITED RELEASE **  User Interface (UI) Misrepresentation o ...)
 	TODO: check
 CVE-2024-51465 (IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2024-48453 (An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to exe ...)
-	TODO: check
+	NOT-FOR-US: INOVANCE AM401_CPU1608TPTN
 CVE-2024-40745 (Reflected Cross site scripting vulnerability in Convert Forms componen ...)
 	TODO: check
 CVE-2024-40744 (Unrestricted file upload via security bypass in Convert Forms componen ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0f036beb385ca341750028572374d69fbfe99fc

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0f036beb385ca341750028572374d69fbfe99fc
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241204/694e4ef8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list