[Git][security-tracker-team/security-tracker][master] Add three cacti issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed May 15 08:23:05 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
640aff05 by Salvatore Bonaccorso at 2024-05-15T09:22:22+02:00
Add three cacti issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -778,13 +778,20 @@ CVE-2024-31443 (Cacti provides an operational monitoring and fault management fr
 CVE-2024-31377 (Unrestricted Upload of File with Dangerous Type vulnerability in J.N.  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-30268 (Cacti provides an operational monitoring and fault management framewor ...)
-	TODO: check
+	- cacti <undetermined>
+	NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-9m3v-whmr-pc2q
+	NOTE: https://github.com/Cacti/cacti/commit/a38b9046e9772612fda847b46308f9391a49891e
+	TODO: check, might be only affecting 1.3.y
 CVE-2024-30259 (FastDDS is a C++ implementation of the DDS (Data Distribution Service) ...)
 	TODO: check
 CVE-2024-30258 (FastDDS is a C++ implementation of the DDS (Data Distribution Service) ...)
 	TODO: check
 CVE-2024-29895 (Cacti provides an operational monitoring and fault management framewor ...)
-	TODO: check
+	- cacti <undetermined>
+	NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-cr28-x256-xf5m
+	NOTE: Fixed by: https://github.com/Cacti/cacti/commit/53e8014d1f082034e0646edc6286cde3800c683d
+	NOTE: But fix reverted again: https://github.com/Cacti/cacti/commit/99633903cad0de5ace636249de16f77e57a3c8fc
+	TODO: check, might affect only 1.3.x
 CVE-2024-29894 (Cacti provides an operational monitoring and fault management framewor ...)
 	TODO: check
 CVE-2024-29513 (An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Foren ...)
@@ -800,7 +807,8 @@ CVE-2024-28277 (In Sourcecodester School Task Manager v1.0, a vulnerability was
 CVE-2024-28276 (Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scr ...)
 	NOT-FOR-US: Sourcecodester School Task Manager
 CVE-2024-27082 (Cacti provides an operational monitoring and fault management framewor ...)
-	TODO: check
+	- cacti <unfixed>
+	NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-j868-7vjp-rp9h
 CVE-2024-25662 (Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 ...)
 	TODO: check
 CVE-2024-25641 (Cacti provides an operational monitoring and fault management framewor ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/640aff051867ae52d516bafd3f42e136ed8b319c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/640aff051867ae52d516bafd3f42e136ed8b319c
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240515/88e0f115/attachment.htm>


More information about the debian-security-tracker-commits mailing list