[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Oct 15 16:01:17 BST 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a657d991 by Moritz Mühlenhoff at 2024-10-15T17:00:48+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -126,7 +126,7 @@ CVE-2024-48119 (Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the modu
 CVE-2024-47885 (The Astro web framework has a DOM Clobbering gadget in the client-side ...)
 	NOT-FOR-US: Astro web framework
 CVE-2024-47831 (Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x,  ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2024-47826 (eLabFTW is an open source electronic lab notebook for research labs. A ...)
 	NOT-FOR-US: eLabFTW
 CVE-2024-47767 (Tuleap is a tool for end to end traceability of application and system ...)
@@ -142,7 +142,7 @@ CVE-2024-46911 (Cross-site Resource Forgery (CSRF), Privilege escalation vulnera
 CVE-2024-46535 (Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability  ...)
 	NOT-FOR-US: Jepaas
 CVE-2024-46528 (An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere ...)
-	TODO: check
+	NOT-FOR-US: KubeSphere
 CVE-2024-45741 (In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud P ...)
 	NOT-FOR-US: Splunk
 CVE-2024-45740 (In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud P ...)
@@ -166,7 +166,7 @@ CVE-2024-45732 (In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions be
 CVE-2024-45731 (In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1. ...)
 	NOT-FOR-US: Splunk
 CVE-2024-43701 (Software installed and run as a non-privileged user may conduct GPU sy ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2024-41997 (An issue was discovered in version of Warp Terminal prior to 2024.07.1 ...)
 	NOT-FOR-US: Warp Terminal
 CVE-2024-40616
@@ -174,7 +174,7 @@ CVE-2024-40616
 CVE-2023-50780 (Apache ActiveMQ Artemis allows access to diagnostic information and co ...)
 	TODO: check
 CVE-2023-48082 (Nagios XI before 5.11.3 2024R1 was discovered to improperly handle API ...)
-	TODO: check
+	NOT-FOR-US: Nagios XI
 CVE-2023-45817
 	REJECTED
 CVE-2024-9924 (The fix for CVE-2024-26261 was incomplete, and and the specific packag ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a657d9911fe9df0af2fa6aca2f25215fd3a7a6f4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a657d9911fe9df0af2fa6aca2f25215fd3a7a6f4
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241015/68840b98/attachment.htm>


More information about the debian-security-tracker-commits mailing list