[Git][security-tracker-team/security-tracker][master] triage older issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Nov 13 20:02:46 GMT 2024
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7ee39762 by Moritz Muehlenhoff at 2024-11-13T21:02:31+01:00
triage older issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11997,7 +11997,7 @@ CVE-2024-47561 (Schema parsing in the Java SDK of Apache Avro 1.11.3 and previou
NOT-FOR-US: Apache Avro
CVE-2024-47554 (Uncontrolled Resource Consumption vulnerability in Apache Commons IO. ...)
- commons-io 2.16.0-1
- [bookworm] - commons-io <no-dsa> (Minor issue)
+ [bookworm] - commons-io <ignored> (Minor issue)
[bullseye] - commons-io <postponed> (Minor issue; can be fixed in next update)
NOTE: https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1
CVE-2024-45872 (Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x41 ...)
@@ -68821,7 +68821,7 @@ CVE-2024-21504 (Versions of the package livewire/livewire from 3.3.5 and before
NOT-FOR-US: livewire
CVE-2024-21503 (Versions of the package black before 24.3.0 are vulnerable to Regular ...)
- black 24.4.0-1 (bug #1067177)
- [bookworm] - black <no-dsa> (Minor issue)
+ [bookworm] - black <ignored> (Minor issue)
[bullseye] - black <no-dsa> (Minor issue)
[buster] - black <postponed> (Minor issue; can be fixed in next update)
NOTE: https://security.snyk.io/vuln/SNYK-PYTHON-BLACK-6256273
@@ -79025,7 +79025,7 @@ CVE-2024-24822 (Pimcore's Admin Classic Bundle provides a backend user interface
NOT-FOR-US: Pimcore's Admin Classic Bundle
CVE-2024-24816 (CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...)
- ckeditor <unfixed> (bug #1063536)
- [bookworm] - ckeditor <no-dsa> (Minor issue)
+ [bookworm] - ckeditor <ignored> (Minor issue, only affects shipped example files)
[bullseye] - ckeditor <no-dsa> (Minor issue)
[buster] - ckeditor <no-dsa> (Minor issue)
- ckeditor3 <unfixed> (bug #1063537; unimportant)
@@ -79034,7 +79034,7 @@ CVE-2024-24816 (CKEditor4 is an open source what-you-see-is-what-you-get HTML ed
[buster] - ckeditor3 <end-of-life> (No longer supported in LTS)
NOTE: https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-mw2c-vx6j-mg76
NOTE: https://github.com/ckeditor/ckeditor4/commit/7518202f0f228ee5549a36ecb7cb880b06ea5add (4.24.0-lts)
- NOTE: The samples are not shipped in ckedito3
+ NOTE: The samples are not shipped in ckeditor3
CVE-2024-24815 (CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...)
- ckeditor <unfixed> (bug #1063536)
[bookworm] - ckeditor <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ee39762bd4ba3df2e3220cc73a95b5928082e79
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ee39762bd4ba3df2e3220cc73a95b5928082e79
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241113/049e089b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list