[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Dec 4 21:04:27 GMT 2024
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a0f036be by Salvatore Bonaccorso at 2024-12-04T22:04:05+01:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,23 +1,23 @@
CVE-2024-8962 (The WPBITS Addons For Elementor Page Builder plugin for WordPress is v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-8894 (Out-of-bounds Writevulnerability was discovered in Open Design Allianc ...)
- TODO: check
+ NOT-FOR-US: Open Design Alliance Drawings SDK
CVE-2024-7488 (Improper Input Validation vulnerability in RestApp Inc. Online Orderin ...)
- TODO: check
+ NOT-FOR-US: RestApp Inc. Online Ordering System
CVE-2024-5020 (Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2024-54158 (In JetBrains YouTrack before 2024.3.52635 potential spoofing attack wa ...)
- TODO: check
+ NOT-FOR-US: JetBrains YouTrack
CVE-2024-54157 (In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible ...)
- TODO: check
+ NOT-FOR-US: JetBrains YouTrack
CVE-2024-54156 (In JetBrains YouTrack before 2024.3.52635 multiple merge functions wer ...)
- TODO: check
+ NOT-FOR-US: JetBrains YouTrack
CVE-2024-54155 (In JetBrains YouTrack before 2024.3.51866 improper access control allo ...)
- TODO: check
+ NOT-FOR-US: JetBrains YouTrack
CVE-2024-54154 (In JetBrains YouTrack before 2024.3.51866 system takeover was possible ...)
- TODO: check
+ NOT-FOR-US: JetBrains YouTrack
CVE-2024-54153 (In JetBrains YouTrack before 2024.3.51866 unauthenticated database bac ...)
- TODO: check
+ NOT-FOR-US: JetBrains YouTrack
CVE-2024-54134 (A publish-access account was compromised for `@solana/web3.js`, a Java ...)
TODO: check
CVE-2024-54132 (The GitHub CLI is GitHub\u2019s official command line tool. A security ...)
@@ -25,29 +25,29 @@ CVE-2024-54132 (The GitHub CLI is GitHub\u2019s official command line tool. A se
CVE-2024-54002 (Dependency-Track is a Component Analysis platform that allows organiza ...)
TODO: check
CVE-2024-53614 (A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attac ...)
- TODO: check
+ NOT-FOR-US: Thinkware Cloud APK
CVE-2024-52676 (Itsourcecode Online Discussion Forum Project v.1.0.0 is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: Itsourcecode Online Discussion Forum Project
CVE-2024-52278
REJECTED
CVE-2024-52277 (User Interface (UI) Misrepresentation of Critical Information vulnerab ...)
- TODO: check
+ NOT-FOR-US: DocuSeal
CVE-2024-52276 (** INITIAL LIMITED RELEASE ** User Interface (UI) Misrepresentation o ...)
TODO: check
CVE-2024-52275 (Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2024-52274 (Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2024-52273 (Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2024-52272 (Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2024-52269 (** INITIAL LIMITED RELEASE ** User Interface (UI) Misrepresentation o ...)
TODO: check
CVE-2024-51465 (IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2024-48453 (An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to exe ...)
- TODO: check
+ NOT-FOR-US: INOVANCE AM401_CPU1608TPTN
CVE-2024-40745 (Reflected Cross site scripting vulnerability in Convert Forms componen ...)
TODO: check
CVE-2024-40744 (Unrestricted file upload via security bypass in Convert Forms componen ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0f036beb385ca341750028572374d69fbfe99fc
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0f036beb385ca341750028572374d69fbfe99fc
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241204/694e4ef8/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list