[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Jun 17 10:02:17 BST 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
21e5c32f by Moritz Muehlenhoff at 2024-06-17T11:01:55+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -19,21 +19,21 @@ CVE-2024-6039 (A vulnerability, which was classified as critical, was found in F
 CVE-2024-5650 (DLL Hijacking vulnerability has been found in CENTUM CAMS Log server p ...)
 	NOT-FOR-US: CENTUM CAMS Log server
 CVE-2024-5163 (Improper permission settings for mobile applications (com.transsion.ca ...)
-	TODO: check
+	NOT-FOR-US: carlcare
 CVE-2024-4305 (The Post Grid Gutenberg Blocks and WordPress Blog Plugin  WordPress pl ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-3236 (The Popup Builder WordPress plugin before 1.1.33 does not sanitise and ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-38396 (An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use o ...)
-	TODO: check
+	NOT-FOR-US: iTerm2
 CVE-2024-36289 (Reusing a nonce, key pair in encryption issue exists in "FreeFrom - th ...)
-	TODO: check
+	NOT-FOR-US: FreeFrom
 CVE-2024-36279 (Reliance on obfuscation or encryption of security-relevant inputs with ...)
-	TODO: check
+	NOT-FOR-US: FreeFrom
 CVE-2024-36277 (Improper verification of cryptographic signature issue exists in "Free ...)
-	TODO: check
+	NOT-FOR-US: FreeFrom
 CVE-2024-34451 (Ghost through 5.85.1 allows remote attackers to bypass an authenticati ...)
-	TODO: check
+	NOT-FOR-US: Ghost
 CVE-2024-38468 (Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorize ...)
 	NOT-FOR-US: Shenzhen Guoxin Synthesis image system
 CVE-2024-38467 (Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorize ...)
@@ -43,13 +43,13 @@ CVE-2024-38466 (Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456
 CVE-2024-38465 (Shenzhen Guoxin Synthesis image system before 8.3.0 allows username en ...)
 	NOT-FOR-US: Shenzhen Guoxin Synthesis image system
 CVE-2024-38462 (iRODS before 4.3.2 provides an msiSendMail function with a problematic ...)
-	TODO: check
+	NOT-FOR-US: iRODS
 CVE-2024-38461 (irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use  ...)
-	TODO: check
+	NOT-FOR-US: iRODS
 CVE-2024-38460 (In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated usi ...)
 	NOT-FOR-US: SonarQube
 CVE-2024-38459 (langchain_experimental (aka LangChain Experimental) before 0.0.61 for  ...)
-	TODO: check
+	NOT-FOR-US: langchain
 CVE-2024-38458 (Xenforo before 2.2.16 allows code injection.)
 	NOT-FOR-US: Xenforo
 CVE-2024-38457 (Xenforo before 2.2.16 allows CSRF.)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21e5c32f5c44d0dd9557b7c076e2fbddb6238685

-- 
This project does not include diff previews in email notifications.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21e5c32f5c44d0dd9557b7c076e2fbddb6238685
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240617/c348b41a/attachment.htm>


More information about the debian-security-tracker-commits mailing list