Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 5f134c4a by Salvatore Bonaccorso at 2018-07-27T07:38:11+02:00 Add new gitlab issues - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== --- a/data/CVE/list +++ b/data/CVE/list @@ -1,3 +1,25 @@ +CVE-2018-14606 [Persistent XSS Milestone Promotion] + - gitlab <unfixed> + [stretch] - gitlab <not-affected> (Only affects 10.6 and later) + NOTE: https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/ +CVE-2018-14605 [Persistent XSS in Branch Name via Web IDE] + - gitlab <unfixed> + [stretch] - gitlab <not-affected> (Only affects 10.7 and later) + NOTE: https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/ +CVE-2018-14604 [Persistent XSS Pipeline Tooltip] + - gitlab <unfixed> + [stretch] - gitlab <not-affected> (Only affects 10.7 and later) + NOTE: https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/ +CVE-2018-14603 [CSRF in System Hooks] + - gitlab <unfixed> + NOTE: https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/ +CVE-2018-14602 [Information Disclosure Prometheus Metrics] + - gitlab <unfixed> + [stretch] - gitlab <not-affected> (Affects 9.0 and later only) + NOTE: https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/ +CVE-2018-14601 [Markdown DoS] + - gitlab <not-affected> (11.1.0 specific regression) + NOTE: https://about.gitlab.com/2018/07/26/security-release-gitlab-11-dot-1-dot-2-released/ CVE-2017-18344 (The timer_create syscall implementation in kernel/time/posix-timers.c ...) - linux 4.14.12-1 [stretch] - linux 4.9.82-1+deb9u1 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/5f134c4a78c5614aa0622508e089a68734a3a3cb -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/5f134c4a78c5614aa0622508e089a68734a3a3cb You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
