Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
18cc2dda by Salvatore Bonaccorso at 2020-06-17T19:35:51+02:00
Remove notes from CVE-2020-10747

Red Hat has withdrawn the assigned CVE and REJECTED it because as
outlined in <https://bugzilla.redhat.com/show_bug.cgi?id=1810160> the
issue is not crossing boundaries and the corresponding update from
<https://pagure.io/freeipa/issue/8326> is considered a configuration
tightening.

In any case the CVE is REJECTED from the assigning CNA (Red Hat) and
will be marked as such soon. Remove the unneded references.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9954,14 +9954,8 @@ CVE-2020-10749 (A vulnerability was found in all 
versions of containernetworking
        NOTE: 
https://github.com/containernetworking/plugins/commit/219eb9e0464761c47383d239aba206da695e1a43
 CVE-2020-10748
        RESERVED
-CVE-2020-10747 [local account takeover/HBAC rules bypass]
-       RESERVED
-       - freeipa <unfixed>
-       NOTE: https://pagure.io/freeipa/issue/8326
-       NOTE: 
https://pagure.io/freeipa/c/4911a3f05514a7c0ac66e4ef5004581cced8519f (master)
-       NOTE: 
https://pagure.io/freeipa/c/930f4b3d1dc03f9e365b007b027d65e146a08f05 (ipa-4-8)
-       NOTE: 
https://pagure.io/freeipa/c/62400d6d240c1bb68987a1ff194ee7cd6c6d3cf0 (ipa-4-6)
-       NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1810160
+CVE-2020-10747
+       REJECTED
 CVE-2020-10746
        RESERVED
 CVE-2020-10745



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18cc2ddae66b7d42540f582affa064bd6a97bd0e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18cc2ddae66b7d42540f582affa064bd6a97bd0e
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to