[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Dec 17 09:16:10 GMT 2024
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6f3f3ff4 by Moritz Muehlenhoff at 2024-12-17T10:12:48+01:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -39,7 +39,7 @@ CVE-2024-37774 (A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1
CVE-2024-37773 (An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows a ...)
NOT-FOR-US: Sunbird DCIM dcTrack
CVE-2024-35230 (GeoServer is an open source software server written in Java that allow ...)
- TODO: check
+ NOT-FOR-US: GeoServer
CVE-2024-29671 (Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 all ...)
NOT-FOR-US: NEXTU FLATA AX1500 Router
CVE-2024-12443 (The CRM Perks \u2013 WordPress HelpDesk Integration \u2013 Zendesk, Fr ...)
@@ -393,7 +393,7 @@ CVE-2024-12089 (A stored Cross-site Scripting (XSS) vulnerability affecting ENOV
CVE-2024-11358 (Mattermost Android Mobile Apps versions <=2.21.0 fail to properly conf ...)
NOT-FOR-US: Mattermost Android Mobile Apps
CVE-2024-11144 (The server lacks thread safety and can be crashed by anomalous data se ...)
- TODO: check
+ NOT-FOR-US: LightFTP
CVE-2024-10972 (Velocidex WinPmem versions 4.1 and below suffer from an Improper Input ...)
NOT-FOR-US: Velocidex WinPmem
CVE-2024-10095 (In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213) ...)
@@ -2737,7 +2737,7 @@ CVE-2024-53785 (Missing Authorization vulnerability in Alexander Volkov Chatter.
CVE-2024-53450 (RAGFlow 0.13.0 suffers from improper access control in document-hooks. ...)
NOT-FOR-US: RAGFlow
CVE-2024-53441 (An issue in the index.js decryptCookie function of cookie-encrypter v1 ...)
- TODO: check
+ NOT-FOR-US: cookie-encrypter
CVE-2024-52599 (Tuleap is an open source suite to improve management of software devel ...)
NOT-FOR-US: Tuleap
CVE-2024-52586 (eLabFTW is an open source electronic lab notebook for research labs. A ...)
@@ -5335,7 +5335,6 @@ CVE-2024-53620 (A cross-site scripting (XSS) vulnerability in the Article module
- spip <unfixed> (bug #1088801)
[bookworm] - spip <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://grimthereaperteam.medium.com/ec1e8714c02e
- TODO: check, maybe fixed in 4.3.4, if so identify fix
CVE-2024-53619 (An authenticated arbitrary file upload vulnerability in the Documents ...)
- spip <unfixed> (bug #1088800)
[bookworm] - spip <postponed> (Minor issue, revisit when fixed upstream)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6f3f3ff4872113378e13dbf20c255c6293a03b87
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6f3f3ff4872113378e13dbf20c255c6293a03b87
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241217/0e57703c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list