Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits: d800e5e6 by Sylvain Beucler at 2023-12-23T09:48:25+01:00 CVE-2023-50250/cacti: buster not-affected - - - - - a65dc34d by Sylvain Beucler at 2023-12-23T09:49:01+01:00 CVE-2023-50569/cacti: most likely duplicate of CVE-2023-50250 - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -104,6 +104,7 @@ CVE-2023-50708 (yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 CVE-2023-50569 (Reflected Cross Site Scripting (XSS) vulnerability in Cacti v1.2.25, a ...) - cacti <unfixed> NOTE: https://gist.github.com/ISHGARD-2/a6b57de899f977e2af41780e7428b4bf + NOTE: Exact same text as GHSA-xwqc-7jc4-xm73 / CVE-2023-50250. CVE-2023-50259 (Medusa is an automatic video library manager for TV shows. Versions pr ...) TODO: check CVE-2023-50258 (Medusa is an automatic video library manager for TV shows. Versions pr ...) @@ -112,7 +113,9 @@ CVE-2023-50254 (Deepin Linux's default document reader `deepin-reader` software - deepin-reader <itp> (bug #970218) CVE-2023-50250 (Cacti is an open source operational monitoring and fault management fr ...) - cacti <unfixed> + [buster] - cacti <not-affected> (Vulnerable code introduced later) NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-xwqc-7jc4-xm73 + NOTE: Introduced by: https://github.com/Cacti/cacti/commit/27a36d48e1cea172b0750c970324208b39d2bec5 (release/1.2.23) CVE-2023-50147 (There is an arbitrary command execution vulnerability in the setDiagno ...) NOT-FOR-US: TOTOLINK CVE-2023-49792 (Nextcloud Server provides data storage for Nextcloud, an open source c ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/78055871a641cd52c6b9248fa85330068f6e10b1...a65dc34d41a35fd4229e03ad1e7682609d53ae34 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/78055871a641cd52c6b9248fa85330068f6e10b1...a65dc34d41a35fd4229e03ad1e7682609d53ae34 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits