Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7a05456b by security tracker role at 2023-04-16T08:10:16+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,13 @@
+CVE-2023-30773
+       RESERVED
+CVE-2023-30771
+       RESERVED
+CVE-2015-10103
+       RESERVED
+CVE-2015-10102
+       RESERVED
+CVE-2015-10101 (A vulnerability classified as problematic was found in Google 
Analytic ...)
+       TODO: check
 CVE-2023-2107 (A vulnerability, which was classified as critical, was found in 
IBOS 4 ...)
        NOT-FOR-US: IBOS
 CVE-2023-2106 (Weak Password Requirements in GitHub repository 
janeczku/calibre-web p ...)
@@ -80,7 +90,7 @@ CVE-2023-2078
        RESERVED
 CVE-2021-46880 (x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD 
before 7.0 er ...)
        - libressl <itp> (bug #754513)
-CVE-2023-30772
+CVE-2023-30772 (The Linux kernel before 6.2.9 has a race condition and 
resultant use-a ...)
        - linux <unfixed> (unimportant)
        NOTE: 
https://git.kernel.org/linus/06615d11cc78162dfd5116efb71f29eb29502d37 (6.3-rc4)
        NOTE: CONFIG_CHARGER_DA9150 not enabled in Debian.
@@ -3094,14 +3104,14 @@ CVE-2023-29511
        RESERVED
 CVE-2023-29510
        RESERVED
-CVE-2023-29509
-       RESERVED
-CVE-2023-29508
-       RESERVED
-CVE-2023-29507
-       RESERVED
-CVE-2023-29506
-       RESERVED
+CVE-2023-29509 (XWiki Commons are technical libraries common to several other 
top leve ...)
+       TODO: check
+CVE-2023-29508 (XWiki Commons are technical libraries common to several other 
top leve ...)
+       TODO: check
+CVE-2023-29507 (XWiki Commons are technical libraries common to several other 
top leve ...)
+       TODO: check
+CVE-2023-29506 (XWiki Commons are technical libraries common to several other 
top leve ...)
+       TODO: check
 CVE-2023-29505
        RESERVED
 CVE-2023-28393
@@ -4078,14 +4088,14 @@ CVE-2023-29216 (In Apache Linkis &lt;=1.3.1, because 
the parameters are not effe
        NOT-FOR-US: Apache Linkis
 CVE-2023-29215 (In Apache Linkis &lt;=1.3.1, due to the lack of effective 
filtering of ...)
        NOT-FOR-US: Apache Linkis
-CVE-2023-29214
-       RESERVED
+CVE-2023-29214 (XWiki Commons are technical libraries common to several other 
top leve ...)
+       TODO: check
 CVE-2023-29213
        RESERVED
-CVE-2023-29212
-       RESERVED
-CVE-2023-29211
-       RESERVED
+CVE-2023-29212 (XWiki Commons are technical libraries common to several other 
top leve ...)
+       TODO: check
+CVE-2023-29211 (XWiki Commons are technical libraries common to several other 
top leve ...)
+       TODO: check
 CVE-2023-29210 (XWiki Commons are technical libraries common to several other 
top leve ...)
        TODO: check
 CVE-2023-29209 (XWiki Commons are technical libraries common to several other 
top leve ...)
@@ -16102,8 +16112,8 @@ CVE-2022-48314
        RESERVED
 CVE-2022-48313
        RESERVED
-CVE-2022-48312
-       RESERVED
+CVE-2022-48312 (The HwPCAssistant module has the out-of-bounds read/write 
vulnerabilit ...)
+       TODO: check
 CVE-2023-25194 (A possible security vulnerability has been identified in 
Apache Kafka  ...)
        - kafka <itp> (bug #786460)
 CVE-2022-4902 (A vulnerability classified as problematic has been found in eXo 
Chat A ...)
@@ -43998,8 +44008,8 @@ CVE-2022-43130
        RESERVED
 CVE-2022-43129
        RESERVED
-CVE-2022-43128
-       RESERVED
+CVE-2022-43128 (Dreamer CMS 4.0.1 allows SQL injection via ArchivesMapper.xml. 
...)
+       TODO: check
 CVE-2022-43127 (Online Diagnostic Lab Management System v1.0 was discovered to 
contain ...)
        NOT-FOR-US: Online Diagnostic Lab Management System
 CVE-2022-43126 (Online Diagnostic Lab Management System v1.0 was discovered to 
contain ...)
@@ -50076,8 +50086,8 @@ CVE-2022-40948
        RESERVED
 CVE-2022-40947
        RESERVED
-CVE-2022-40946
-       RESERVED
+CVE-2022-40946 (On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 
devices, i ...)
+       TODO: check
 CVE-2022-40945
        RESERVED
 CVE-2022-40944 (Dairy Farm Shop Management System 1.0 is vulnerable to SQL 
Injection v ...)
@@ -55362,10 +55372,10 @@ CVE-2022-38843 (EspoCRM version 7.1.8 is vulnerable 
to Unrestricted File Upload
        NOT-FOR-US: EspoCRM
 CVE-2022-38842
        RESERVED
-CVE-2022-38841
-       RESERVED
-CVE-2022-38840
-       RESERVED
+CVE-2022-38841 (Linksys AX3200 1.1.00 is vulnerable to OS command injection by 
authent ...)
+       TODO: check
+CVE-2022-38840 (cgi-bin/xmlstatus.cgi in G&#252;ralp MAN-EAM-0003 3.2.4 is 
vulnerable  ...)
+       TODO: check
 CVE-2022-38839
        RESERVED
 CVE-2022-38838
@@ -58759,8 +58769,7 @@ CVE-2022-37706 (enlightenment_sys in Enlightenment 
before 0.25.4 allows local us
        - e17 0.25.4-1
        NOTE: https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit
        NOTE: 
https://git.enlightenment.org/enlightenment/enlightenment/commit/cc7faeccf77fef8b0ae70e312a21e4cde087e141
-CVE-2022-37705
-       RESERVED
+CVE-2022-37705 (A privilege escalation flaw was found in Amanda 3.5.1 in which 
the bac ...)
        - amanda 1:3.5.1-10 (bug #1029829)
        [bullseye] - amanda <no-dsa> (Minor issue)
        [buster] - amanda <no-dsa> (Minor issue)
@@ -58769,8 +58778,7 @@ CVE-2022-37705
        NOTE: https://marc.info/?l=amanda-hackers&m=167437716918603&w=2
        NOTE: https://github.com/zmanda/amanda/pull/196
        NOTE: 
https://github.com/zmanda/amanda/commit/43c5b32f46186f3ed78fe6c7503096fa9ad1236c
-CVE-2022-37704
-       RESERVED
+CVE-2022-37704 (Amanda 3.5.1 allows privilege escalation from the regular user 
backup  ...)
        {DLA-3330-1}
        - amanda 1:3.5.1-10 (bug #1029829)
        [bullseye] - amanda <no-dsa> (Minor issue)
@@ -59852,8 +59860,8 @@ CVE-2022-37308 (OX App Suite through 7.10.6 allows XSS 
via HTML in text/plain e-
        NOT-FOR-US: OX App Suite
 CVE-2022-37307 (OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a 
snippet,  ...)
        NOT-FOR-US: OX App Suite
-CVE-2022-37306
-       RESERVED
+CVE-2022-37306 (OX App Suite before 7.10.6-rev30 allows XSS via an upsell 
trigger. ...)
+       TODO: check
 CVE-2022-37305 (The Remote Keyless Entry (RKE) receiving unit on certain Honda 
vehicle ...)
        NOT-FOR-US: Remote Keyless Entry (RKE) receiving unit on Honda vehicles
 CVE-2022-36426
@@ -60106,8 +60114,8 @@ CVE-2022-37257 (Prototype pollution vulnerability in 
function convertLater in np
        NOT-FOR-US: stealjs
 CVE-2022-37256
        RESERVED
-CVE-2022-37255
-       RESERVED
+CVE-2022-37255 (TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video 
feed vi ...)
+       TODO: check
 CVE-2022-37254 (DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) 
via Backg ...)
        NOT-FOR-US: DolphinPHP
 CVE-2022-37253 (Persistent cross-site scripting (XSS) in Crime Reporting 
System 1.0 al ...)
@@ -60244,8 +60252,7 @@ CVE-2022-37188
        RESERVED
 CVE-2022-37187
        RESERVED
-CVE-2022-37186 [Session destroyed on portal but still valid on handlers]
-       RESERVED
+CVE-2022-37186 (In LemonLDAP::NG before 2.0.15. some sessions are not deleted 
when the ...)
        {DLA-3287-1}
        - lemonldap-ng 2.0.15+ds-1
        [bullseye] - lemonldap-ng 2.0.11+ds-4+deb11u2
@@ -68745,14 +68752,14 @@ CVE-2022-34130
        RESERVED
 CVE-2022-34129
        RESERVED
-CVE-2022-34128
-       RESERVED
-CVE-2022-34127
-       RESERVED
-CVE-2022-34126
-       RESERVED
-CVE-2022-34125
-       RESERVED
+CVE-2022-34128 (The Cartography (aka positions) plugin before 6.0.1 for GLPI 
allows re ...)
+       TODO: check
+CVE-2022-34127 (The Managentities plugin before 4.0.2 for GLPI allows reading 
local fi ...)
+       TODO: check
+CVE-2022-34126 (The Activity plugin before 3.1.1 for GLPI allows reading local 
files v ...)
+       TODO: check
+CVE-2022-34125 (front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI 
allows at ...)
+       TODO: check
 CVE-2022-34124
        RESERVED
 CVE-2022-34123
@@ -80088,8 +80095,8 @@ CVE-2022-30078 (NETGEAR R6200_V2 firmware versions 
through R6200v2-V1.0.3.12_10.
        NOT-FOR-US: Netgear
 CVE-2022-30077
        RESERVED
-CVE-2022-30076
-       RESERVED
+CVE-2022-30076 (ENTAB ERP 1.0 allows attackers to discover users' full names 
via a bru ...)
+       TODO: check
 CVE-2022-30075 (In TP-Link Router AX50 firmware 210730 and older, import of a 
maliciou ...)
        NOT-FOR-US: TP-Link
 CVE-2022-30074
@@ -85043,8 +85050,8 @@ CVE-2022-28355 (randomUUID in Scala.js before 1.10.0 
generates predictable value
        NOT-FOR-US: Scala.js
 CVE-2022-28354
        RESERVED
-CVE-2022-28353
-       RESERVED
+CVE-2022-28353 (In the External Redirect Warning Plugin 1.3 for MyBB, the 
redirect URL ...)
+       TODO: check
 CVE-2022-1210 (A vulnerability classified as problematic was found in LibTIFF 
4.3.0.  ...)
        - tiff <unfixed> (unimportant)
        [bullseye] - tiff <no-dsa> (Minor issue)
@@ -106779,8 +106786,7 @@ CVE-2021-4159 (A vulnerability was found in the Linux 
kernel's EBPF verifier whe
        - linux 5.7.6-1
        [stretch] - linux <ignored> (Too risky to backport, and mitigated by 
default)
        NOTE: Fixed by: 
https://git.kernel.org/linus/294f2fc6da27620a506e6c050241655459ccd6bd (5.7-rc1)
-CVE-2021-45464 [hypervisor escape and host code execution]
-       RESERVED
+CVE-2021-45464 (kvmtool through 39181fc allows an out-of-bounds write, related 
to virt ...)
        - kvmtool <removed> (bug #1006290)
        NOTE: https://www.kalmarunionen.dk/writeups/2021/hxp-2021/lkvm/
 CVE-2021-45463 (load_cache in GEGL before 0.4.34 allows shell expansion when a 
pathnam ...)
@@ -114538,8 +114544,7 @@ CVE-2021-43614
        RESERVED
 CVE-2021-43613
        RESERVED
-CVE-2021-43612 [crash in SONMP decoder]
-       RESERVED
+CVE-2021-43612 (In lldpd before 1.0.13, when decoding SONMP packets in the 
sonmp_decod ...)
        {DLA-3389-1}
        - lldpd 1.0.13-1
        [bullseye] - lldpd 1.0.11-1+deb11u1
@@ -128073,8 +128078,8 @@ CVE-2021-39297 (Potential vulnerabilities have been 
identified in UEFI firmware
        NOT-FOR-US: HP
 CVE-2021-39296 (In OpenBMC 2.9, crafted IPMI messages allow an attacker to 
bypass auth ...)
        NOT-FOR-US: OpenBMC
-CVE-2021-39295
-       RESERVED
+CVE-2021-39295 (In OpenBMC 2.9, crafted IPMI messages allow an attacker to 
cause a den ...)
+       TODO: check
 CVE-2021-3727 (# Vulnerability in `rand-quote` and `hitokoto` plugins 
**Description** ...)
        NOT-FOR-US: ohmyzsh
 CVE-2021-3726 (# Vulnerability in `title` function **Description**: the 
`title` funct ...)
@@ -135163,8 +135168,8 @@ CVE-2021-36522
        RESERVED
 CVE-2021-36521
        RESERVED
-CVE-2021-36520
-       RESERVED
+CVE-2021-36520 (A SQL injection vulnerability in I-Tech Trainsmart r1044 
exists via a  ...)
+       TODO: check
 CVE-2021-36519
        RESERVED
 CVE-2021-36518
@@ -140435,8 +140440,7 @@ CVE-2021-34339 (Ming 0.4.8 has an out-of-bounds 
buffer access issue in the funct
 CVE-2021-34338 (Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the 
function ...)
        - ming <removed>
        NOTE: https://github.com/libming/libming/issues/201
-CVE-2021-34337 [password checking timing attack in administrative REST API]
-       RESERVED
+CVE-2021-34337 (An issue was discovered in Mailman Core before 3.3.5. An 
attacker with ...)
        - mailman3 3.3.7-1 (bug #1004934)
        [bullseye] - mailman3 <no-dsa> (Minor issue)
        [buster] - mailman3 <no-dsa> (Minor issue; will be fixed via point 
release)
@@ -141181,8 +141185,8 @@ CVE-2021-33992
        RESERVED
 CVE-2021-33991
        RESERVED
-CVE-2021-33990
-       RESERVED
+CVE-2021-33990 (Liferay Portal 6.2.5 allows 
Command=FileUpload&amp;Type=File&amp;Curre ...)
+       TODO: check
 CVE-2021-33989
        RESERVED
 CVE-2021-33988 (Cross Site Scripting (XSS). vulnerability exists in Microweber 
CMS 1.2 ...)
@@ -151628,8 +151632,7 @@ CVE-2021-30154 (An issue was discovered in MediaWiki 
before 1.31.12 and 1.32.x t
        [stretch] - mediawiki <not-affected> (Vulnerable code introduced later)
        NOTE: https://phabricator.wikimedia.org/T278014
        NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/674083/
-CVE-2021-30153
-       RESERVED
+CVE-2021-30153 (An issue was discovered in the VisualEditor extension in 
MediaWiki bef ...)
        - mediawiki 1:1.35.2-1
        [buster] - mediawiki <not-affected> (Vulnerable code not present)
        [stretch] - mediawiki <not-affected> (Vulnerable code not present)
@@ -182912,8 +182915,7 @@ CVE-2020-29009
        RESERVED
 CVE-2020-29008
        RESERVED
-CVE-2020-29007
-       RESERVED
+CVE-2020-29007 (The Score extension through 0.3.0 for MediaWiki has a remote 
code exec ...)
        NOT-FOR-US: Score MediaWiki extension
        NOTE: 
https://seqred.pl/en/cve-2020-29007-remote-code-execution-in-mediawiki-score/
        NOTE: https://phabricator.wikimedia.org/T257062
@@ -187814,8 +187816,7 @@ CVE-2020-28165 (The EasyCorp ZenTao PMS 12.4.2 
application suffers from an arbit
        NOT-FOR-US: EasyCorp ZenTao PMS
 CVE-2020-28164
        RESERVED
-CVE-2020-28163
-       RESERVED
+CVE-2020-28163 (libdwarf before 20201201 allows a dwarf_print_lines.c NULL 
pointer der ...)
        - dwarfutils 20201201-1
        [buster] - dwarfutils <ignored> (Minor issue)
        [stretch] - dwarfutils <ignored> (Minor issue)
@@ -190214,8 +190215,7 @@ CVE-2020-27547
        RESERVED
 CVE-2020-27546
        RESERVED
-CVE-2020-27545
-       RESERVED
+CVE-2020-27545 (libdwarf before 20201017 has a one-byte out-of-bounds read 
because of  ...)
        - dwarfutils 20201201-1
        [buster] - dwarfutils <ignored> (Minor issue)
        [stretch] - dwarfutils <ignored> (Minor issue)
@@ -212874,8 +212874,7 @@ CVE-2020-17356
        RESERVED
 CVE-2020-17355 (Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x 
before 4.23. ...)
        NOT-FOR-US: Arista
-CVE-2020-17354
-       RESERVED
+CVE-2020-17354 (LilyPond before 2.24 allows attackers to bypass the -dsafe 
protection  ...)
        - lilypond 2.22.1-1
        [bullseye] - lilypond <ignored> (Unfixable, marked as insecure in later 
uploads)
        [buster] - lilypond <ignored> (Unfixable, marked as insecure in later 
uploads)
@@ -272111,16 +272110,14 @@ CVE-2019-14946 (The ultimate-member plugin before 
2.0.52 for WordPress has XSS r
        NOT-FOR-US: ultimate-member plugin for WordPress
 CVE-2019-14945 (The ultimate-member plugin before 2.0.54 for WordPress has 
XSS. ...)
        NOT-FOR-US: ultimate-member plugin for WordPress
-CVE-2019-14944 [Multiple Command-Line Flag Injection Vulnerabilities]
-       RESERVED
+CVE-2019-14944 (An issue was discovered in GitLab Community and Enterprise 
Edition bef ...)
        [experimental] - gitlab 11.11.8+dfsg-1
        - gitlab 12.6.8-3 (bug #934708)
        NOTE: 
https://about.gitlab.com/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/
 CVE-2019-14943 (An issue was discovered in GitLab Community and Enterprise 
Edition 12. ...)
        - gitlab <not-affected> (Only affects GitLab CE/EE 12.0 and later)
        NOTE: 
https://about.gitlab.com/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/
-CVE-2019-14942 [Insecure Cookie Handling on GitLab Pages]
-       RESERVED
+CVE-2019-14942 (An issue was discovered in GitLab Community and Enterprise 
Edition bef ...)
        [experimental] - gitlab 11.11.8+dfsg-1
        - gitlab 12.6.8-3 (bug #934708)
        NOTE: 
https://about.gitlab.com/2019/08/12/critical-security-release-gitlab-12-dot-1-dot-6-released/
@@ -320981,8 +320978,7 @@ CVE-2018-17886 (An issue was discovered in JEESNS 
1.3. The XSS filter in com.lxi
        NOT-FOR-US: JEESNS
 CVE-2018-17885
        RESERVED
-CVE-2018-17883
-       RESERVED
+CVE-2018-17883 (An issue was discovered in Open Ticket Request System (OTRS) 
6.0.x bef ...)
        - otrs2 6.0.12-1
        [stretch] - otrs2 <not-affected> (Only affects 6.x)
        [jessie] - otrs2 <not-affected> (Only affects 6.x)
@@ -321757,14 +321753,12 @@ CVE-2018-17539 (The BGP daemon (bgpd) in all IP 
Infusion ZebOS versions to 7.10.
        NOT-FOR-US: BGP daemon (bgpd) in IP Infusion ZebOS and OcNOS
 CVE-2018-17538 (** DISPUTED ** Axon (formerly TASER International) Evidence 
Sync 3.15. ...)
        NOT-FOR-US: Axon Evidence Sync
-CVE-2018-17537 [Persistent XSS package.json]
-       RESERVED
+CVE-2018-17537 (An issue was discovered in GitLab Community and Enterprise 
Edition bef ...)
        [experimental] - gitlab 11.1.8+dfsg-1
        - gitlab 11.1.8+dfsg-2
        [stretch] - gitlab <not-affected> (Only affects 10.4 and later)
        NOTE: 
https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17536 [Persistent XSS merge request project import]
-       RESERVED
+CVE-2018-17536 (An issue was discovered in GitLab Community and Enterprise 
Edition bef ...)
        [experimental] - gitlab 11.1.8+dfsg-1
        - gitlab 11.1.8+dfsg-2
        [stretch] - gitlab <not-affected> (Only affects 10.4 and later)
@@ -321982,42 +321976,35 @@ CVE-2018-17456 (Git before 2.14.5, 2.15.x before 
2.15.3, 2.16.x before 2.16.5, 2
        NOTE: 
https://git.kernel.org/pub/scm/git/git.git/commit/?id=273c61496f88c6495b886acb1041fe57965151da
        NOTE: 
https://git.kernel.org/pub/scm/git/git.git/commit/?id=a124133e1e6ab5c7a9fef6d0e6bcb084e3455b46
        NOTE: 
https://git.kernel.org/pub/scm/git/git.git/commit/?id=1a7fd1fb2998002da6e9ff2ee46e1bdd25ee8404
-CVE-2018-17455 [IDOR merge request approvals]
-       RESERVED
+CVE-2018-17455 (An issue was discovered in GitLab Enterprise Edition before 
11.1.7, 11 ...)
        [experimental] - gitlab 11.1.8+dfsg-1
        - gitlab 11.1.8+dfsg-2
        NOTE: 
https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17454 [Persistent XSS on issue details]
-       RESERVED
+CVE-2018-17454 (An issue was discovered in GitLab Community and Enterprise 
Edition bef ...)
        [experimental] - gitlab 11.1.8+dfsg-1
        - gitlab 11.1.8+dfsg-2
        [stretch] - gitlab <not-affected> (Only affects 9.3 and later)
        NOTE: 
https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17453 [GRPC::Unknown logging token disclosure]
-       RESERVED
+CVE-2018-17453 (An issue was discovered in GitLab Community and Enterprise 
Edition bef ...)
        [experimental] - gitlab 11.1.8+dfsg-1
        - gitlab 11.1.8+dfsg-2
        [stretch] - gitlab <not-affected> (Only affects 10.4 and later)
        NOTE: 
https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17452 [validate_localhost function in url_blocker.rb could be 
bypassed]
-       RESERVED
+CVE-2018-17452 (An issue was discovered in GitLab Community and Enterprise 
Edition bef ...)
        [experimental] - gitlab 11.1.8+dfsg-1
        - gitlab 11.1.8+dfsg-2
        NOTE: 
https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17451 [Slack integration CSRF Oauth2]
-       RESERVED
+CVE-2018-17451 (An issue was discovered in GitLab Community and Enterprise 
Edition bef ...)
        [experimental] - gitlab 11.1.8+dfsg-1
        - gitlab 11.1.8+dfsg-2
        [stretch] - gitlab <not-affected> (Only affects 9.4 and later)
        NOTE: 
https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17450 [SSRF GCP access token disclosure]
-       RESERVED
+CVE-2018-17450 (An issue was discovered in GitLab Community and Enterprise 
Edition bef ...)
        [experimental] - gitlab 11.1.8+dfsg-1
        - gitlab 11.1.8+dfsg-2
        [stretch] - gitlab <not-affected> (Only affects 10.2 and later)
        NOTE: 
https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/
-CVE-2018-17449 [Confidential information disclosure in events API endpoint]
-       RESERVED
+CVE-2018-17449 (An issue was discovered in GitLab Community and Enterprise 
Edition bef ...)
        [experimental] - gitlab 11.1.8+dfsg-1
        - gitlab 11.1.8+dfsg-2
        [stretch] - gitlab <not-affected> (Only affects 9.3 and later)
@@ -327331,8 +327318,7 @@ CVE-2018-15475
        RESERVED
 CVE-2018-15474 (** DISPUTED ** CSV Injection (aka Excel Macro Injection or 
Formula Inj ...)
        NOTE: Dokuwiki non-issue
-CVE-2018-15472 [Diff formatter DoS in Sidekiq jobs]
-       RESERVED
+CVE-2018-15472 (An issue was discovered in GitLab Community and Enterprise 
Edition bef ...)
        [experimental] - gitlab 11.1.8+dfsg-1
        - gitlab 11.1.8+dfsg-2
        NOTE: 
https://about.gitlab.com/2018/10/01/security-release-gitlab-11-dot-3-dot-1-released/



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a05456b48000a9df119924f158450ca33d5524b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a05456b48000a9df119924f158450ca33d5524b
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to