[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2023-49086/cacti: fix patch
Sylvain Beucler (@beuc)
beuc at debian.org
Sat Feb 3 11:53:02 GMT 2024
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
02a813f5 by Sylvain Beucler at 2024-02-03T12:51:45+01:00
CVE-2023-49086/cacti: fix patch
- - - - -
d4bc509a by Sylvain Beucler at 2024-02-03T12:51:47+01:00
CVE-2023-49088/cacti: reference patch
- - - - -
99492343 by Sylvain Beucler at 2024-02-03T12:51:49+01:00
CVE-2023-50569/cacti: reference MITRE duplicate request
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7503,6 +7503,7 @@ CVE-2023-50569 (Reflected Cross Site Scripting (XSS) vulnerability in Cacti v1.2
NOTE: https://gist.github.com/ISHGARD-2/a6b57de899f977e2af41780e7428b4bf
NOTE: Introduced by: https://github.com/Cacti/cacti/commit/27a36d48e1cea172b0750c970324208b39d2bec5 (release/1.2.23)
NOTE: Exact same text as GHSA-xwqc-7jc4-xm73 / CVE-2023-50250.
+ NOTE: Duplicate reported at MITRE 2024-01-18 (CVE Request 1589347)
CVE-2023-50259 (Medusa is an automatic video library manager for TV shows. Versions pr ...)
NOT-FOR-US: Medusa (not same as src:medusa)
CVE-2023-50258 (Medusa is an automatic video library manager for TV shows. Versions pr ...)
@@ -7534,6 +7535,7 @@ CVE-2023-49088 (Cacti is an open source operational monitoring and fault managem
NOTE: Caused by an incomplete fix for CVE-2023-39515
NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-q7g7-gcf6-wh4x
NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-hrg9-qqqx-wc4h (CVE-2023-39515)
+ NOTE: https://github.com/Cacti/cacti/commit/56f9d99e6e5ab434ea18fa344236f41e78f99c59 (1.2.x)
CVE-2023-49085 (Cacti provides an operational monitoring and fault management framewor ...)
- cacti 1.2.26+ds1-1
NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-vr3c-38wh-g855
@@ -7653,7 +7655,7 @@ CVE-2023-49677 (Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL In
CVE-2023-49086 (Cacti is a robust performance and fault management framework and a fro ...)
- cacti 1.2.26+ds1-1 (bug #1059254)
NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-wc73-r2vw-59pr
- NOTE: https://github.com/Cacti/cacti/commit/58a980f335980ab57659420053d89d4e721ae3fc
+ NOTE: https://github.com/Cacti/cacti/commit/56f9d99e6e5ab434ea18fa344236f41e78f99c59 (1.2.x)
CVE-2023-49084 (Cacti is a robust performance and fault management framework and a fro ...)
- cacti 1.2.26+ds1-1 (bug #1059254)
NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ee909d6caf9a47b7eaffd69491f5bc87f0c3a28a...994923433124524845df850fb0f1624d7a73ac3c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ee909d6caf9a47b7eaffd69491f5bc87f0c3a28a...994923433124524845df850fb0f1624d7a73ac3c
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240203/70ba4415/attachment.htm>
More information about the debian-security-tracker-commits
mailing list