[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Dec 17 09:16:10 GMT 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6f3f3ff4 by Moritz Muehlenhoff at 2024-12-17T10:12:48+01:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -39,7 +39,7 @@ CVE-2024-37774 (A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1
 CVE-2024-37773 (An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows a ...)
 	NOT-FOR-US: Sunbird DCIM dcTrack
 CVE-2024-35230 (GeoServer is an open source software server written in Java that allow ...)
-	TODO: check
+	NOT-FOR-US: GeoServer
 CVE-2024-29671 (Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 all ...)
 	NOT-FOR-US: NEXTU FLATA AX1500 Router
 CVE-2024-12443 (The CRM Perks \u2013 WordPress HelpDesk Integration \u2013 Zendesk, Fr ...)
@@ -393,7 +393,7 @@ CVE-2024-12089 (A stored Cross-site Scripting (XSS) vulnerability affecting ENOV
 CVE-2024-11358 (Mattermost Android Mobile Apps versions <=2.21.0 fail to properly conf ...)
 	NOT-FOR-US: Mattermost Android Mobile Apps
 CVE-2024-11144 (The server lacks thread safety and can be crashed by anomalous data se ...)
-	TODO: check
+	NOT-FOR-US: LightFTP
 CVE-2024-10972 (Velocidex WinPmem versions 4.1 and below suffer from an Improper Input ...)
 	NOT-FOR-US: Velocidex WinPmem
 CVE-2024-10095 (In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213) ...)
@@ -2737,7 +2737,7 @@ CVE-2024-53785 (Missing Authorization vulnerability in Alexander Volkov Chatter.
 CVE-2024-53450 (RAGFlow 0.13.0 suffers from improper access control in document-hooks. ...)
 	NOT-FOR-US: RAGFlow
 CVE-2024-53441 (An issue in the index.js decryptCookie function of cookie-encrypter v1 ...)
-	TODO: check
+	NOT-FOR-US: cookie-encrypter
 CVE-2024-52599 (Tuleap is an open source suite to improve management of software devel ...)
 	NOT-FOR-US: Tuleap
 CVE-2024-52586 (eLabFTW is an open source electronic lab notebook for research labs. A ...)
@@ -5335,7 +5335,6 @@ CVE-2024-53620 (A cross-site scripting (XSS) vulnerability in the Article module
 	- spip <unfixed> (bug #1088801)
 	[bookworm] - spip <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://grimthereaperteam.medium.com/ec1e8714c02e
-	TODO: check, maybe fixed in 4.3.4, if so identify fix
 CVE-2024-53619 (An authenticated arbitrary file upload vulnerability in the Documents  ...)
 	- spip <unfixed> (bug #1088800)
 	[bookworm] - spip <postponed> (Minor issue, revisit when fixed upstream)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6f3f3ff4872113378e13dbf20c255c6293a03b87

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6f3f3ff4872113378e13dbf20c255c6293a03b87
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241217/0e57703c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list