Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
998c711c by Salvatore Bonaccorso at 2023-08-31T10:32:23+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13,9 +13,9 @@ CVE-2023-4650 (Improper Access Control in GitHub repository 
instantsoft/icms2 pr
 CVE-2023-4649 (Session Fixation in GitHub repository instantsoft/icms2 prior 
to 2.16. ...)
        TODO: check
 CVE-2023-4500 (The Order Tracking Pro plugin for WordPress is vulnerable to 
Stored Cr ...)
-       TODO: check
+       NOT-FOR-US: Order Tracking Pro plugin for WordPress
 CVE-2023-4471 (The Order Tracking Pro plugin for WordPress is vulnerable to 
Reflected ...)
-       TODO: check
+       NOT-FOR-US: Order Tracking Pro plugin for WordPress
 CVE-2023-4315 (The Woo Custom Emails for WordPress is vulnerable to Reflected 
Cross-S ...)
        TODO: check
 CVE-2023-4245 (The WooCommerce PDF Invoice Builder for WordPress is vulnerable 
to una ...)
@@ -27,9 +27,9 @@ CVE-2023-4162 (A  segmentation fault can occur in Brocade 
Fabric OS after Brocad
 CVE-2023-4161 (The WooCommerce PDF Invoice Builder for WordPress is vulnerable 
to Cro ...)
        TODO: check
 CVE-2023-4160 (The WooCommerce PDF Invoice Builder plugin for WordPress is 
vulnerable ...)
-       TODO: check
+       NOT-FOR-US: WooCommerce PDF Invoice Builder plugin for WordPress
 CVE-2023-4000 (The Waiting: One-click countdowns plugin for WordPress is 
vulnerable t ...)
-       TODO: check
+       NOT-FOR-US: Waiting: One-click countdowns plugin for WordPress
 CVE-2023-41163 (A Reflected Cross-site scripting (XSS) vulnerability in the 
file manag ...)
        TODO: check
 CVE-2023-41041 (Graylog is a free and open log management platform. In a 
multi-node Gr ...)
@@ -37,19 +37,19 @@ CVE-2023-41041 (Graylog is a free and open log management 
platform. In a multi-n
 CVE-2023-41040 (GitPython is a python library used to interact with Git 
repositories.  ...)
        TODO: check
 CVE-2023-3999 (The Waiting: One-click countdowns plugin for WordPress is 
vulnerable t ...)
-       TODO: check
+       NOT-FOR-US: Waiting: One-click countdowns plugin for WordPress
 CVE-2023-3764 (The WooCommerce PDF Invoice Builder plugin for WordPress is 
vulnerable ...)
-       TODO: check
+       NOT-FOR-US: WooCommerce PDF Invoice Builder plugin for WordPress
 CVE-2023-3677 (The WooCommerce PDF Invoice Builder plugin for WordPress is 
vulnerable ...)
-       TODO: check
+       NOT-FOR-US: WooCommerce PDF Invoice Builder plugin for WordPress
 CVE-2023-3636 (The WP Project Manager plugin for WordPress is vulnerable to 
privilege ...)
-       TODO: check
+       NOT-FOR-US: WP Project Manager plugin for WordPress
 CVE-2023-3489 (The  firmwaredownload command on Brocade Fabric OS v9.2.0 could 
log th ...)
        TODO: check
 CVE-2023-3404 (The ProfileGrid plugin for WordPress is vulnerable to 
unauthorized dec ...)
-       TODO: check
+       NOT-FOR-US: ProfileGrid plugin for WordPress
 CVE-2023-3162 (The Stripe Payment Plugin for WooCommerce plugin for WordPress 
is vuln ...)
-       TODO: check
+       NOT-FOR-US: Stripe Payment Plugin for WooCommerce plugin for WordPress
 CVE-2023-39139 (An issue in Archive v3.3.7 allows attackers to execute a path 
traversa ...)
        TODO: check
 CVE-2023-39138 (An issue in ZIPFoundation v0.9.16 allows attackers to execute 
a path t ...)
@@ -71,11 +71,11 @@ CVE-2023-31424 (Brocade SANnav Web interface before Brocade 
SANnav v2.3.0 and v2
 CVE-2023-31423 (Possible  information exposure through log file vulnerability 
where se ...)
        TODO: check
 CVE-2023-2354 (The CHP Ads Block Detector plugin for WordPress is vulnerable 
to Store ...)
-       TODO: check
+       NOT-FOR-US: CHP Ads Block Detector plugin for WordPress
 CVE-2023-2353 (The CHP Ads Block Detector plugin for WordPress is vulnerable 
to unaut ...)
-       TODO: check
+       NOT-FOR-US: CHP Ads Block Detector plugin for WordPress
 CVE-2023-2352 (The CHP Ads Block Detector plugin for WordPress is vulnerable 
to Cross ...)
-       TODO: check
+       NOT-FOR-US: CHP Ads Block Detector plugin for WordPress
 CVE-2023-4640 (The controller responsible for setting the logging level does 
not incl ...)
        TODO: check
 CVE-2023-4624 (Server-Side Request Forgery (SSRF) in GitHub repository 
bookstackapp/b ...)
@@ -14402,7 +14402,7 @@ CVE-2023-2281 (When archiving a team, Mattermost fails 
to sanitize the related W
 CVE-2023-2280 (The WP Directory Kit plugin for WordPress is vulnerable to 
unauthorize ...)
        NOT-FOR-US: WordPress plugin
 CVE-2023-2279 (The WP Directory Kit plugin for WordPress is vulnerable to 
Cross-Site  ...)
-       TODO: check
+       NOT-FOR-US: WP Directory Kit plugin for WordPress
 CVE-2023-2278 (The WP Directory Kit plugin for WordPress is vulnerable to 
Local File  ...)
        NOT-FOR-US: WP Directory Kit plugin for WordPress
 CVE-2023-2277 (The WP Directory Kit plugin for WordPress is vulnerable to 
Cross-Site  ...)
@@ -15389,13 +15389,13 @@ CVE-2022-4943
 CVE-2023-2175
        RESERVED
 CVE-2023-2174 (The BadgeOS plugin for WordPress is vulnerable to unauthorized 
modific ...)
-       TODO: check
+       NOT-FOR-US: BadgeOS plugin for WordPress
 CVE-2023-2173 (The BadgeOS plugin for WordPress is vulnerable to Insecure 
Direct Obje ...)
-       TODO: check
+       NOT-FOR-US: BadgeOS plugin for WordPress
 CVE-2023-2172 (The BadgeOS plugin for WordPress is vulnerable to Insecure 
Direct Obje ...)
-       TODO: check
+       NOT-FOR-US: BadgeOS plugin for WordPress
 CVE-2023-2171 (The BadgeOS plugin for WordPress is vulnerable to Stored 
Cross-Site Sc ...)
-       TODO: check
+       NOT-FOR-US: BadgeOS plugin for WordPress
 CVE-2023-2170 (The TaxoPress plugin for WordPress is vulnerable to Stored 
Cross-Site  ...)
        NOT-FOR-US: TaxoPress plugin for WordPress
 CVE-2023-2169 (The TaxoPress plugin for WordPress is vulnerable to Stored 
Cross-Site  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/998c711c6e294de25ea282df41f3a7679c1590f9

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/998c711c6e294de25ea282df41f3a7679c1590f9
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to