[Git][security-tracker-team/security-tracker][master] Reassign some CVEs with grocy, itp'ed entry

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 20:45:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8bf68d21 by Salvatore Bonaccorso at 2026-08-05T21:44:02+02:00
Reassign some CVEs with grocy, itp'ed entry

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -256105,11 +256105,11 @@ CVE-2024-55553 (In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are r
 	NOTE: Backport in opensourcerouting fork for 8.4 branch:
 	NOTE: https://github.com/opensourcerouting/frr/commit/cc1c66a7e8dd31c681f396f6635192c0d60a543c
 CVE-2024-55076 (Grocy through 4.3.0 has no CSRF protection, as demonstrated by changin ...)
-	NOT-FOR-US: Grocy
+	- grocy <itp> (bug #969056)
 CVE-2024-55075 (Grocy through 4.3.0 allows remote attackers to obtain sensitive inform ...)
-	NOT-FOR-US: Grocy
+	- grocy <itp> (bug #969056)
 CVE-2024-55074 (The edit profile function of Grocy through 4.3.0 allows stored XSS and ...)
-	NOT-FOR-US: Grocy
+	- grocy <itp> (bug #969056)
 CVE-2024-54767 (An access control issue in the component /juis_boxinfo.xml of AVM FRIT ...)
 	NOT-FOR-US: AVM FRITZ!Box 7530 AX
 CVE-2024-54764 (An access control issue in the component /login/hostinfo2.cgi of ipTIM ...)
@@ -290360,7 +290360,7 @@ CVE-2024-44947 (In the Linux kernel, the following vulnerability has been resolv
 	NOTE: https://git.kernel.org/linus/3c0da3d163eb32f1f91891efaade027fa9b245b9 (6.11-rc4)
 	NOTE: https://project-zero.issues.chromium.org/issues/42451729
 CVE-2024-8370 (A vulnerability classified as problematic was found in Grocy up to 4.2 ...)
-	NOT-FOR-US: Grocy
+	- grocy <itp> (bug #969056)
 CVE-2024-8365 (Vault Community Edition and Vault Enterprise experienced a regression  ...)
 	NOT-FOR-US: HashiCorp Vault
 CVE-2024-7871 (SQL Injection in online dictionary function of Easytest Online Test Pl ...)
@@ -377732,7 +377732,7 @@ CVE-2023-42398 (An issue in zzCMS v.2023 allows a remote attacker to execute arb
 CVE-2023-42362 (An arbitrary file upload vulnerability in Teller Web App v.4.4.0 allow ...)
 	NOT-FOR-US: Teller Web App
 CVE-2023-42270 (Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).)
-	NOT-FOR-US: Grocy
+	- grocy <itp> (bug #969056)
 CVE-2023-41889 (SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHI ...)
 	NOT-FOR-US: SHIRASAGI
 CVE-2023-41887 (OpenRefine is a powerful free, open source tool for working with messy ...)
@@ -617300,7 +617300,7 @@ CVE-2020-15254 (Crossbeam is a set of tools for concurrent programming. In cross
 	NOTE: https://github.com/crossbeam-rs/crossbeam/security/advisories/GHSA-v5m7-53cv-f3hx
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2020-45/#CVE-2020-15254
 CVE-2020-15253 (Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via  ...)
-	NOT-FOR-US: Grocy
+	- grocy <itp> (bug #969056)
 CVE-2020-15252 (In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right ( ...)
 	NOT-FOR-US: XWiki
 CVE-2020-15251 (In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bf68d218d83e3f3e10310025cacd2597cce660e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bf68d218d83e3f3e10310025cacd2597cce660e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/3413e89f/attachment.htm>


More information about the debian-security-tracker-commits mailing list