Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ea71b6bd by Moritz Muehlenhoff at 2023-03-10T12:03:52+01:00
new gitlab issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2105,7 +2105,7 @@ CVE-2023-1086
CVE-2023-1085
RESERVED
CVE-2023-1084 (An issue has been discovered in GitLab CE/EE affecting all
versions be ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2023-1083
RESERVED
CVE-2023-1082
@@ -2239,7 +2239,7 @@ CVE-2023-1073
NOTE:
https://git.kernel.org/linus/b12fece4c64857e5fab4290bf01b2e0317a88456
NOTE: https://www.openwall.com/lists/oss-security/2023/01/17/3
CVE-2023-1072 (An issue has been discovered in GitLab affecting all versions
starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2023-1071
RESERVED
CVE-2023-1070 (External Control of File Name or Path in GitHub repository
nilsteampas ...)
@@ -9812,7 +9812,7 @@ CVE-2023-0485
CVE-2023-0484
RESERVED
CVE-2023-0483 (An issue has been discovered in GitLab affecting all versions
starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2023-0482 (In RESTEasy the insecure File.createTempFile() is used in the
DataSour ...)
- resteasy <unfixed> (bug #1031728)
- resteasy3.0 <unfixed> (bug #1031729)
@@ -13128,7 +13128,7 @@ CVE-2023-0225
CVE-2023-0224
RESERVED
CVE-2023-0223 (An issue has been discovered in GitLab affecting all versions
starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-4886
RESERVED
CVE-2022-48255 (There is a system command injection vulnerability in
BiSheng-WNM FW 3. ...)
@@ -15524,7 +15524,7 @@ CVE-2023-0051 (Heap-based Buffer Overflow in GitHub
repository vim/vim prior to
NOTE:
https://github.com/vim/vim/commit/c32949b0779106ed5710ae3bffc5053e49083ab4
(v9.0.1144)
NOTE: Crash in CLI tool, no security impact
CVE-2023-0050 (An issue has been discovered in GitLab affecting all versions
starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2023-0049 (Out-of-bounds Read in GitHub repository vim/vim prior to
9.0.1143. ...)
- vim 2:9.0.1378-1 (unimportant)
NOTE: https://huntr.dev/bounties/5e6f325c-ba54-4bf0-b050-dca048fd3fd9
@@ -20294,7 +20294,7 @@ CVE-2022-4464 (Themify Portfolio Post WordPress plugin
before 1.2.1 does not val
CVE-2022-4463
RESERVED
CVE-2022-4462 (An issue has been discovered in GitLab affecting all versions
starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-4461
RESERVED
CVE-2022-4460 (The Sidebar Widgets by CodeLights WordPress plugin through 1.4
does no ...)
@@ -22097,7 +22097,7 @@ CVE-2022-4333
CVE-2022-4332
RESERVED
CVE-2022-4331 (An issue has been discovered in GitLab EE affecting all
versions start ...)
- TODO: check
+ - gitlab <not-affected> (Specific to EE)
CVE-2022-4330 (The WP Attachments WordPress plugin through 5.0.5 does not
sanitise an ...)
NOT-FOR-US: WordPress plugin
CVE-2022-4329 (The Product list Widget for Woocommerce WordPress plugin
through 1.0 d ...)
@@ -22391,11 +22391,11 @@ CVE-2022-4318
RESERVED
- cri-o <itp> (bug #979702)
CVE-2022-4317 (An issue has been discovered in GitLab DAST analyzer affecting
all ver ...)
- TODO: check
+ NOT-FOR-US: Gitlab DAST analyzer
CVE-2022-4316
RESERVED
CVE-2022-4315 (An issue has been discovered in GitLab DAST analyzer affecting
all ver ...)
- TODO: check
+ NOT-FOR-US: Gitlab DAST analyzer
CVE-2022-4314 (Improper Privilege Management in GitHub repository
ikus060/rdiffweb pr ...)
- rdiffweb <itp> (bug #969974)
CVE-2022-4313
@@ -22988,7 +22988,7 @@ CVE-2022-4291 (The aswjsflt.dll library from Avast
Antivirus windows contained a
CVE-2022-4290
RESERVED
CVE-2022-4289 (An issue has been discovered in GitLab affecting all versions
starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-4288
RESERVED
CVE-2022-4287 (Authentication bypass in local application lock feature in
Devolutions ...)
@@ -25981,7 +25981,7 @@ CVE-2022-4009
CVE-2022-4008
RESERVED
CVE-2022-4007 (A issue has been discovered in GitLab CE/EE affecting all
versions fro ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-4006 (A vulnerability, which was classified as problematic, has been
found i ...)
NOT-FOR-US: WBCE CMS
CVE-2022-4005 (The Donation Button WordPress plugin through 4.0.0 does not
sanitize a ...)
@@ -30184,7 +30184,7 @@ CVE-2022-3760 (Improper Neutralization of Special
Elements used in an SQL Comman
CVE-2022-3759 (An issue has been discovered in GitLab CE/EE affecting all
versions st ...)
- gitlab <unfixed>
CVE-2022-3758 (An issue has been discovered in GitLab affecting all versions
starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-44418
RESERVED
CVE-2022-44417
@@ -38837,7 +38837,7 @@ CVE-2022-41617 (In versions 16.1.x before 16.1.3.1,
15.1.x before 15.1.6.1, 14.1
CVE-2022-36795 (In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before
16.1.3.1, 15. ...)
NOT-FOR-US: F5 BIG-IP
CVE-2022-3381 (An issue has been discovered in GitLab affecting all versions
starting ...)
- TODO: check
+ - gitlab <unfixed>
CVE-2022-3380 (The Customizer Export/Import WordPress plugin before 0.9.5
unserialize ...)
NOT-FOR-US: WordPress plugin
CVE-2022-3379 (Horner Automation's Cscape version 9.90 SP7 and prior does not
properl ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea71b6bda0a2606cb7d04a39f512f30187394fb8
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ea71b6bda0a2606cb7d04a39f512f30187394fb8
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits