[Git][security-tracker-team/security-tracker][master] Reassign some CVEs with grocy, itp'ed entry
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 5 20:45:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8bf68d21 by Salvatore Bonaccorso at 2026-08-05T21:44:02+02:00
Reassign some CVEs with grocy, itp'ed entry
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -256105,11 +256105,11 @@ CVE-2024-55553 (In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are r
NOTE: Backport in opensourcerouting fork for 8.4 branch:
NOTE: https://github.com/opensourcerouting/frr/commit/cc1c66a7e8dd31c681f396f6635192c0d60a543c
CVE-2024-55076 (Grocy through 4.3.0 has no CSRF protection, as demonstrated by changin ...)
- NOT-FOR-US: Grocy
+ - grocy <itp> (bug #969056)
CVE-2024-55075 (Grocy through 4.3.0 allows remote attackers to obtain sensitive inform ...)
- NOT-FOR-US: Grocy
+ - grocy <itp> (bug #969056)
CVE-2024-55074 (The edit profile function of Grocy through 4.3.0 allows stored XSS and ...)
- NOT-FOR-US: Grocy
+ - grocy <itp> (bug #969056)
CVE-2024-54767 (An access control issue in the component /juis_boxinfo.xml of AVM FRIT ...)
NOT-FOR-US: AVM FRITZ!Box 7530 AX
CVE-2024-54764 (An access control issue in the component /login/hostinfo2.cgi of ipTIM ...)
@@ -290360,7 +290360,7 @@ CVE-2024-44947 (In the Linux kernel, the following vulnerability has been resolv
NOTE: https://git.kernel.org/linus/3c0da3d163eb32f1f91891efaade027fa9b245b9 (6.11-rc4)
NOTE: https://project-zero.issues.chromium.org/issues/42451729
CVE-2024-8370 (A vulnerability classified as problematic was found in Grocy up to 4.2 ...)
- NOT-FOR-US: Grocy
+ - grocy <itp> (bug #969056)
CVE-2024-8365 (Vault Community Edition and Vault Enterprise experienced a regression ...)
NOT-FOR-US: HashiCorp Vault
CVE-2024-7871 (SQL Injection in online dictionary function of Easytest Online Test Pl ...)
@@ -377732,7 +377732,7 @@ CVE-2023-42398 (An issue in zzCMS v.2023 allows a remote attacker to execute arb
CVE-2023-42362 (An arbitrary file upload vulnerability in Teller Web App v.4.4.0 allow ...)
NOT-FOR-US: Teller Web App
CVE-2023-42270 (Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).)
- NOT-FOR-US: Grocy
+ - grocy <itp> (bug #969056)
CVE-2023-41889 (SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHI ...)
NOT-FOR-US: SHIRASAGI
CVE-2023-41887 (OpenRefine is a powerful free, open source tool for working with messy ...)
@@ -617300,7 +617300,7 @@ CVE-2020-15254 (Crossbeam is a set of tools for concurrent programming. In cross
NOTE: https://github.com/crossbeam-rs/crossbeam/security/advisories/GHSA-v5m7-53cv-f3hx
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2020-45/#CVE-2020-15254
CVE-2020-15253 (Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via ...)
- NOT-FOR-US: Grocy
+ - grocy <itp> (bug #969056)
CVE-2020-15252 (In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right ( ...)
NOT-FOR-US: XWiki
CVE-2020-15251 (In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bf68d218d83e3f3e10310025cacd2597cce660e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bf68d218d83e3f3e10310025cacd2597cce660e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/3413e89f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list