[Git][security-tracker-team/security-tracker][master] new gitlab issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Dec 13 08:39:46 GMT 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6826509d by Moritz Muehlenhoff at 2024-12-13T09:39:24+01:00
new gitlab issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -60,7 +60,7 @@ CVE-2024-8647 (An issue was discovered in GitLab affecting all versions starting
 CVE-2024-8233 (An issue has been discovered in GitLab CE/EE affecting all versions fr ...)
 	- gitlab <unfixed>
 CVE-2024-8179 (An issue has been discovered in GitLab CE/EE affecting all versions fr ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2024-55888 (Hush Line is an open-source whistleblower management system. Starting  ...)
 	NOT-FOR-US: Hush Line
 CVE-2024-55886 (OpenSearch Data Prepper is a component of the OpenSearch project that  ...)
@@ -175,13 +175,13 @@ CVE-2024-21575 (ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue s
 CVE-2024-21574 (The issue stems from a missing validation of the pip field in a POST r ...)
 	NOT-FOR-US: ComfyUI-Impact-Pack
 CVE-2024-12570 (An issue has been discovered in GitLab CE/EE affecting all versions st ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2024-12401 (A flaw was found in the cert-manager package. This flaw allows an atta ...)
 	NOT-FOR-US: Open Shift
 CVE-2024-12333 (The Woodmart theme for WordPress is vulnerable to arbitrary shortcode  ...)
 	NOT-FOR-US: WordPress theme
 CVE-2024-12292 (An issue was discovered in GitLab CE/EE affecting all versions startin ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2024-12271 (The 360 Javascript Viewer plugin for WordPress is vulnerable to Stored ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-12160 (The Seraphinite Bulk Discounts for WooCommerce plugin for WordPress is ...)
@@ -189,9 +189,9 @@ CVE-2024-12160 (The Seraphinite Bulk Discounts for WooCommerce plugin for WordPr
 CVE-2024-11760 (The Currency Converter Widget \u26a1 PRO plugin for WordPress is vulne ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-11274 (An issue was discovered in GitLab CE/EE affecting all versions startin ...)
-	TODO: check
+	- gitlab <unfixed>
 CVE-2024-10043 (An issue has been discovered in GitLab EE affecting all versions start ...)
-	TODO: check
+	- gitlab <not-affected> (Specific to EE)
 CVE-2024-55633 (Improper Authorization vulnerability in Apache Superset. On Postgres a ...)
 	NOT-FOR-US: Apache Superset
 CVE-2024-9881 (The LearnPress  WordPress plugin before 4.2.7.2 does not sanitise and  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6826509d490110112cb6f12ce80c0af5b89fdda5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6826509d490110112cb6f12ce80c0af5b89fdda5
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241213/2476fee7/attachment.htm>


More information about the debian-security-tracker-commits mailing list