[Git][security-tracker-team/security-tracker][master] triage older issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Nov 13 20:02:46 GMT 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7ee39762 by Moritz Muehlenhoff at 2024-11-13T21:02:31+01:00
triage older issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11997,7 +11997,7 @@ CVE-2024-47561 (Schema parsing in the Java SDK of Apache Avro 1.11.3 and previou
 	NOT-FOR-US: Apache Avro
 CVE-2024-47554 (Uncontrolled Resource Consumption vulnerability in Apache Commons IO.  ...)
 	- commons-io 2.16.0-1
-	[bookworm] - commons-io <no-dsa> (Minor issue)
+	[bookworm] - commons-io <ignored> (Minor issue)
 	[bullseye] - commons-io <postponed> (Minor issue; can be fixed in next update)
 	NOTE: https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1
 CVE-2024-45872 (Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x41 ...)
@@ -68821,7 +68821,7 @@ CVE-2024-21504 (Versions of the package livewire/livewire from 3.3.5 and before
 	NOT-FOR-US: livewire
 CVE-2024-21503 (Versions of the package black before 24.3.0 are vulnerable to Regular  ...)
 	- black 24.4.0-1 (bug #1067177)
-	[bookworm] - black <no-dsa> (Minor issue)
+	[bookworm] - black <ignored> (Minor issue)
 	[bullseye] - black <no-dsa> (Minor issue)
 	[buster] - black <postponed> (Minor issue; can be fixed in next update)
 	NOTE: https://security.snyk.io/vuln/SNYK-PYTHON-BLACK-6256273
@@ -79025,7 +79025,7 @@ CVE-2024-24822 (Pimcore's Admin Classic Bundle provides a backend user interface
 	NOT-FOR-US: Pimcore's Admin Classic Bundle
 CVE-2024-24816 (CKEditor4 is an open source what-you-see-is-what-you-get HTML editor.  ...)
 	- ckeditor <unfixed> (bug #1063536)
-	[bookworm] - ckeditor <no-dsa> (Minor issue)
+	[bookworm] - ckeditor <ignored> (Minor issue, only affects shipped example files)
 	[bullseye] - ckeditor <no-dsa> (Minor issue)
 	[buster] - ckeditor <no-dsa> (Minor issue)
 	- ckeditor3 <unfixed> (bug #1063537; unimportant)
@@ -79034,7 +79034,7 @@ CVE-2024-24816 (CKEditor4 is an open source what-you-see-is-what-you-get HTML ed
 	[buster] - ckeditor3 <end-of-life> (No longer supported in LTS)
 	NOTE: https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-mw2c-vx6j-mg76
 	NOTE: https://github.com/ckeditor/ckeditor4/commit/7518202f0f228ee5549a36ecb7cb880b06ea5add (4.24.0-lts)
-	NOTE: The samples are not shipped in ckedito3
+	NOTE: The samples are not shipped in ckeditor3
 CVE-2024-24815 (CKEditor4 is an open source what-you-see-is-what-you-get HTML editor.  ...)
 	- ckeditor <unfixed> (bug #1063536)
 	[bookworm] - ckeditor <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ee39762bd4ba3df2e3220cc73a95b5928082e79

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ee39762bd4ba3df2e3220cc73a95b5928082e79
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241113/049e089b/attachment.htm>


More information about the debian-security-tracker-commits mailing list