[Git][security-tracker-team/security-tracker][master] 2 commits: Add reference to upstream tag for CVE-2024-43800

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 11 19:28:42 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2851dbd3 by Salvatore Bonaccorso at 2024-09-11T20:23:07+02:00
Add reference to upstream tag for CVE-2024-43800

- - - - -
1c6b6b09 by Salvatore Bonaccorso at 2024-09-11T20:27:30+02:00
Add CVE-2024-837{2,3}/angular.js

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -282,8 +282,8 @@ CVE-2024-44087 (A vulnerability has been identified in Automation License Manage
 CVE-2024-43800 (serve-static serves static files. serve-static passes untrusted user i ...)
 	- node-serve-static <unfixed>
 	NOTE: https://github.com/expressjs/serve-static/security/advisories/GHSA-cm22-4g7w-348p
-	NOTE: https://github.com/expressjs/serve-static/commit/0c11fad159898cdc69fd9ab63269b72468ecaf6b (1.x)
-	NOTE: https://github.com/expressjs/serve-static/commit/ce730896fddce1588111d9ef6fdf20896de5c6fa (v2.1.0)
+	NOTE: https://github.com/expressjs/serve-static/commit/0c11fad159898cdc69fd9ab63269b72468ecaf6b (1.16.0)
+	NOTE: https://github.com/expressjs/serve-static/commit/ce730896fddce1588111d9ef6fdf20896de5c6fa (2.1.0)
 CVE-2024-43799 (Send is a library for streaming files from the file system as a http r ...)
 	- node-send <unfixed>
 	NOTE: https://github.com/pillarjs/send/security/advisories/GHSA-m6fv-jmcg-4jfg
@@ -663,9 +663,11 @@ CVE-2024-8604 (A vulnerability classified as problematic has been found in Sourc
 CVE-2024-8601 (This vulnerability exists in TechExcel Back Office Software versions p ...)
 	NOT-FOR-US: TechExcel Back Office Software
 CVE-2024-8373 (Improper sanitization of the value of the [srcset] attribute in <sourc ...)
-	TODO: check
+	- angular.js <unfixed>
+	NOTE: https://codepen.io/herodevs/full/bGPQgMp/8da9ce87e99403ee13a295c305ebfa0b
 CVE-2024-8372 (Improper sanitization of the value of the '[srcset]' attribute in Angu ...)
-	TODO: check
+	- angular.js <unfixed>
+	NOTE: https://codepen.io/herodevs/full/xxoQRNL/0072e627abe03e9cda373bc75b4c1017
 CVE-2024-8042 (Rapid7 Insight Platform versions between November 2019 and August 14,  ...)
 	NOT-FOR-US: Rapid7 Insight Platform
 CVE-2024-7341 (A session fixation issue was discovered in the SAML adapters provided  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/aa8f0d38b504f2b821af6c161ac28f9882eeab11...1c6b6b093dc954ffb9aaaf4b4586602c3d23876a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/aa8f0d38b504f2b821af6c161ac28f9882eeab11...1c6b6b093dc954ffb9aaaf4b4586602c3d23876a
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240911/2befdaa4/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list