[Git][security-tracker-team/security-tracker][master] Process some more NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu May 1 21:37:28 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
95d085aa by Salvatore Bonaccorso at 2025-05-01T22:37:09+02:00
Process some more NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -148,25 +148,25 @@ CVE-2025-27007 (Incorrect Privilege Assignment vulnerability in Brainstorm Force
 CVE-2025-25016 (Unrestricted file upload in Kibana allows an authenticated attacker to ...)
 	- kibana <itp> (bug #700337)
 CVE-2025-24522 (KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authent ...)
-	TODO: check
+	NOT-FOR-US: KUNBUS Revolution Pi OS Bookworm
 CVE-2025-23254 (NVIDIA TensorRT-LLM for any platform contains a vulnerability in pytho ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA TensorRT-LLM
 CVE-2025-23246 (NVIDIA vGPU software for Windows and Linux contains a vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2025-23245 (NVIDIA vGPU software for Windows and Linux contains a vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2025-1529 (The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-52979 (Uncontrolled Resource Consumption in Elasticsearch while evaluating sp ...)
 	TODO: check
 CVE-2024-52976 (Inclusion of functionality from an untrusted control sphere in Elastic ...)
-	TODO: check
+	NOT-FOR-US: Elastic Agent
 CVE-2024-11994 (APM server logs could contain parts of the document body from a partia ...)
-	TODO: check
+	NOT-FOR-US: APM server
 CVE-2024-11390 (Unrestricted upload of a file with dangerous type in Kibana can lead t ...)
 	- kibana <itp> (bug #700337)
 CVE-2023-46669 (Exposure of sensitive information to local unauthorized actors in Elas ...)
-	TODO: check
+	NOT-FOR-US: Elastic Agent and Elastic Security Endpoint
 CVE-2022-49931 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
 	- linux 6.0.8-1
 	[bullseye] - linux 5.10.158-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/95d085aa0fa2d73cd79aa24acd5f625ecad31944

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/95d085aa0fa2d73cd79aa24acd5f625ecad31944
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250501/3f3687ed/attachment.htm>


More information about the debian-security-tracker-commits mailing list