[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Mar 22 08:03:59 GMT 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
66944a1d by Moritz Muehlenhoff at 2024-03-22T09:03:11+01:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -22,7 +22,7 @@ CVE-2024-2464 (This issue occurs during password recovery, where a difference in
 CVE-2024-2463 (Weak password recovery mechanism in CDeX application allows to retriev ...)
 	NOT-FOR-US: CDeX
 CVE-2024-29937 (NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and Free ...)
-	TODO: check
+	NOT-FOR-US: OpenBSD/FreeBSD
 CVE-2024-29916 (The dormakaba Saflok system before the November 2023 software update a ...)
 	NOT-FOR-US: dormakaba Saflok system
 CVE-2024-29880 (In JetBrains TeamCity before 2023.11 users with access to the agent ma ...)
@@ -54,11 +54,11 @@ CVE-2024-29732 (A SQL Injection has been found on SCAN_VISIO eDocument Suite Web
 CVE-2024-29374 (A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3. ...)
 	- moodle <removed>
 CVE-2024-29244 (Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discover ...)
-	TODO: check
+	NOT-FOR-US: Shenzhen Libituo Technology
 CVE-2024-29243 (Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discover ...)
-	TODO: check
+	NOT-FOR-US: Shenzhen Libituo Technology
 CVE-2024-29180 (Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware  ...)
-	TODO: check
+	NOT-FOR-US: Node webpack-dev-middleware
 CVE-2024-29019 (ESPHome is a system to control microcontrollers remotely through Home  ...)
 	NOT-FOR-US: ESPHome
 CVE-2024-28402 (TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-s ...)
@@ -366,7 +366,7 @@ CVE-2023-41038 (Firebird is a relational database. Versions 4.0.0 through 4.0.3
 CVE-2023-35888 (IBM Security Verify Governance 10.0.2 could allow a remote attacker to ...)
 	NOT-FOR-US: IBM
 CVE-2022-4963 (A vulnerability was found in Folio Spring Module Core up to 1.1.5. It  ...)
-	TODO: check
+	NOT-FOR-US: Folio Spring Module Core
 CVE-2024-2631 (Inappropriate implementation in iOS in Google Chrome prior to 123.0.63 ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
@@ -543,7 +543,7 @@ CVE-2024-28092 (UBEE DDW365 XCNDDW365 8.14.3105 software on hardware 3.13.1 allo
 CVE-2024-24336 (A multiple Cross-site scripting (XSS) vulnerability in the '/members/m ...)
 	NOT-FOR-US: Koha Library Management System
 CVE-2024-22258 (Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2 ...)
-	TODO: check
+	NOT-FOR-US: Spring Authorization Server
 CVE-2024-22085 (An issue was discovered in Elspec G5 digital fault recorder versions 1 ...)
 	NOT-FOR-US: Elspec G5 digital fault recorder
 CVE-2024-22084 (An issue was discovered in Elspec G5 digital fault recorder versions 1 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66944a1daad677387de022dbfcffdc5cee3e789d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66944a1daad677387de022dbfcffdc5cee3e789d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240322/66039f33/attachment.htm>


More information about the debian-security-tracker-commits mailing list