Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d800e5e6 by Sylvain Beucler at 2023-12-23T09:48:25+01:00
CVE-2023-50250/cacti: buster not-affected

- - - - -
a65dc34d by Sylvain Beucler at 2023-12-23T09:49:01+01:00
CVE-2023-50569/cacti: most likely duplicate of CVE-2023-50250

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -104,6 +104,7 @@ CVE-2023-50708 (yii2-authclient is an extension that adds 
OpenID, OAuth, OAuth2
 CVE-2023-50569 (Reflected Cross Site Scripting (XSS) vulnerability in Cacti 
v1.2.25, a ...)
        - cacti <unfixed>
        NOTE: https://gist.github.com/ISHGARD-2/a6b57de899f977e2af41780e7428b4bf
+       NOTE: Exact same text as GHSA-xwqc-7jc4-xm73 / CVE-2023-50250.
 CVE-2023-50259 (Medusa is an automatic video library manager for TV shows. 
Versions pr ...)
        TODO: check
 CVE-2023-50258 (Medusa is an automatic video library manager for TV shows. 
Versions pr ...)
@@ -112,7 +113,9 @@ CVE-2023-50254 (Deepin Linux's default document reader 
`deepin-reader` software
        - deepin-reader <itp> (bug #970218)
 CVE-2023-50250 (Cacti is an open source operational monitoring and fault 
management fr ...)
        - cacti <unfixed>
+       [buster] - cacti <not-affected> (Vulnerable code introduced later)
        NOTE: 
https://github.com/Cacti/cacti/security/advisories/GHSA-xwqc-7jc4-xm73
+       NOTE: Introduced by: 
https://github.com/Cacti/cacti/commit/27a36d48e1cea172b0750c970324208b39d2bec5 
(release/1.2.23)
 CVE-2023-50147 (There is an arbitrary command execution vulnerability in the 
setDiagno ...)
        NOT-FOR-US: TOTOLINK
 CVE-2023-49792 (Nextcloud Server provides data storage for Nextcloud, an open 
source c ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/78055871a641cd52c6b9248fa85330068f6e10b1...a65dc34d41a35fd4229e03ad1e7682609d53ae34

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/78055871a641cd52c6b9248fa85330068f6e10b1...a65dc34d41a35fd4229e03ad1e7682609d53ae34
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to