Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
66bc6291 by Moritz Muehlenhoff at 2023-12-21T15:43:36+01:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,13 @@
+CVE-2023-48291
+       - airflow <itp> (bug #819700)
+CVE-2023-47265
+       - airflow <itp> (bug #819700)
+CVE-2023-49920
+       - airflow <itp> (bug #819700)
+CVE-2023-50783
+       - airflow <itp> (bug #819700)
+CVE-2023-51656
+       NOT-FOR-US: Apache IoTDB
 CVE-2023-XXXX [RUSTSEC-2023-0075]
        - rust-unsafe-libyaml <unfixed>
        NOTE: https://rustsec.org/advisories/RUSTSEC-2023-0075.html
@@ -50,7 +60,7 @@ CVE-2023-48433 (Online Voting System Project v1.0 is 
vulnerable to multiple Unau
 CVE-2023-47093 (An issue was discovered in Stormshield Network Security (SNS) 
4.0.0 th ...)
        NOT-FOR-US: Stormshield Network Security (SNS)
 CVE-2023-46131 (Grails is a framework used to build web applications with the 
Groovy p ...)
-       TODO: check
+       - grails <itp> (bug #473213)
 CVE-2023-45703 (HCL Launch may mishandle input validation of an uploaded 
archive file  ...)
        NOT-FOR-US: HCL
 CVE-2023-45700 (HCL Launch is vulnerable to HTML injection. This vulnerability 
may all ...)
@@ -97,7 +107,7 @@ CVE-2023-51457 (Adobe Experience Manager versions 6.5.18 and 
earlier are affecte
 CVE-2023-50628 (Buffer Overflow vulnerability in libming version 0.4.8, allows 
attacke ...)
        - ming <removed>
 CVE-2023-50249 (Sentry-Javascript is official Sentry SDKs for JavaScript. A 
ReDoS (Reg ...)
-       TODO: check
+       NOT-FOR-US: Sentry-Javascript
 CVE-2023-50044 (Buffer Overflow vulnerability in Cesanta MJS version 2.22.0, 
allows at ...)
        NOT-FOR-US: Cesenta MJS
 CVE-2023-49825 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
@@ -153,7 +163,7 @@ CVE-2023-40204 (Unrestricted Upload of File with Dangerous 
Type vulnerability in
 CVE-2023-40010 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
        NOT-FOR-US: WordPress plugin
 CVE-2023-3742 (Insufficient policy enforcement in ADB in Google Chrome on 
ChromeOS pr ...)
-       TODO: check
+       NOT-FOR-US: Google Chrome on ChromeOS
 CVE-2023-38519 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
        NOT-FOR-US: WordPress plugin
 CVE-2023-38513 (Authorization Bypass Through User-Controlled Key vulnerability 
in Jord ...)
@@ -38415,11 +38425,11 @@ CVE-2023-29489 (An issue was discovered in cPanel 
before 11.109.9999.116. XSS ca
 CVE-2023-29488
        RESERVED
 CVE-2023-29487 (An issue was discovered in Heimdal Thor agent versions 3.4.2 
and befor ...)
-       TODO: check
+       NOT-FOR-US: Heimdal Thor
 CVE-2023-29486 (An issue was discovered in Heimdal Thor agent versions 3.4.2 
and befor ...)
-       TODO: check
+       NOT-FOR-US: Heimdal Thor
 CVE-2023-29485 (An issue was discovered in Heimdal Thor agent versions 3.4.2 
and befor ...)
-       TODO: check
+       NOT-FOR-US: Heimdal Thor
 CVE-2023-29484 (In Terminalfour before 8.3.16, misconfigured LDAP users are 
able to lo ...)
        NOT-FOR-US: Terminalfour
 CVE-2023-29483
@@ -65915,7 +65925,7 @@ CVE-2022-41834
 CVE-2020-36611 (Incorrect Default Permissions vulnerability in Hitachi Tuning 
Manager  ...)
        NOT-FOR-US: Hitachi
 CVE-2023-0011 (A flaw in the input validation in TOBY-L2 allows a user to 
execute arb ...)
-       TODO: check
+       NOT-FOR-US: TOBY-L2
 CVE-2022-47193
        RESERVED
 CVE-2022-47192 (Generex UPS CS141 below 2.06 version, could allow a remote 
attacker to ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66bc6291e062b20d168e8c070df0adca56b2c91f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66bc6291e062b20d168e8c070df0adca56b2c91f
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to