[Git][security-tracker-team/security-tracker][master] Mark CVE-2023-4380 after confirmation from Red Hat

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Feb 21 21:00:25 GMT 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
78e561b7 by Salvatore Bonaccorso at 2024-02-21T21:42:10+01:00
Mark CVE-2023-4380 after confirmation from Red Hat

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -32127,12 +32127,7 @@ CVE-2023-40217 (An issue was discovered in Python before 3.8.18, 3.9.x before 3.
 	NOTE: 1. https://github.com/python/cpython/commit/64f99350351bc46e016b2286f36ba7cd669b79e3
 	NOTE: 2. https://github.com/python/cpython/commit/592bacb6fc0833336c0453e818e9b95016e9fd47
 CVE-2023-4380 (A logic flaw exists in Ansible Automation platform. Whenever a private ...)
-	- ansible <unfixed> (bug #1051897)
-	[bookworm] - ansible <no-dsa> (Minor issue)
-	[bullseye] - ansible <no-dsa> (Minor issue)
-	[buster] - ansible <no-dsa> (Minor issue)
-	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2232324
-	NOTE: likely in awx component or may be RedHat specific
+	NOT-FOR-US: automation-eda-controller
 CVE-2023-4420 (A remote unprivileged attacker can intercept the communication via e.g ...)
 	NOT-FOR-US: SICK LMS5xx
 CVE-2023-4419 (The LMS5xx uses hard-coded credentials, which potentially allow low-sk ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/78e561b7f2a6bff48b4a0da1c97bbfa2ea87398e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/78e561b7f2a6bff48b4a0da1c97bbfa2ea87398e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240221/cef05275/attachment.htm>


More information about the debian-security-tracker-commits mailing list