Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2851dbd3 by Salvatore Bonaccorso at 2024-09-11T20:23:07+02:00
Add reference to upstream tag for CVE-2024-43800

- - - - -
1c6b6b09 by Salvatore Bonaccorso at 2024-09-11T20:27:30+02:00
Add CVE-2024-837{2,3}/angular.js

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -282,8 +282,8 @@ CVE-2024-44087 (A vulnerability has been identified in 
Automation License Manage
 CVE-2024-43800 (serve-static serves static files. serve-static passes 
untrusted user i ...)
        - node-serve-static <unfixed>
        NOTE: 
https://github.com/expressjs/serve-static/security/advisories/GHSA-cm22-4g7w-348p
-       NOTE: 
https://github.com/expressjs/serve-static/commit/0c11fad159898cdc69fd9ab63269b72468ecaf6b
 (1.x)
-       NOTE: 
https://github.com/expressjs/serve-static/commit/ce730896fddce1588111d9ef6fdf20896de5c6fa
 (v2.1.0)
+       NOTE: 
https://github.com/expressjs/serve-static/commit/0c11fad159898cdc69fd9ab63269b72468ecaf6b
 (1.16.0)
+       NOTE: 
https://github.com/expressjs/serve-static/commit/ce730896fddce1588111d9ef6fdf20896de5c6fa
 (2.1.0)
 CVE-2024-43799 (Send is a library for streaming files from the file system as 
a http r ...)
        - node-send <unfixed>
        NOTE: 
https://github.com/pillarjs/send/security/advisories/GHSA-m6fv-jmcg-4jfg
@@ -663,9 +663,11 @@ CVE-2024-8604 (A vulnerability classified as problematic 
has been found in Sourc
 CVE-2024-8601 (This vulnerability exists in TechExcel Back Office Software 
versions p ...)
        NOT-FOR-US: TechExcel Back Office Software
 CVE-2024-8373 (Improper sanitization of the value of the [srcset] attribute in 
<sourc ...)
-       TODO: check
+       - angular.js <unfixed>
+       NOTE: 
https://codepen.io/herodevs/full/bGPQgMp/8da9ce87e99403ee13a295c305ebfa0b
 CVE-2024-8372 (Improper sanitization of the value of the '[srcset]' attribute 
in Angu ...)
-       TODO: check
+       - angular.js <unfixed>
+       NOTE: 
https://codepen.io/herodevs/full/xxoQRNL/0072e627abe03e9cda373bc75b4c1017
 CVE-2024-8042 (Rapid7 Insight Platform versions between November 2019 and 
August 14,  ...)
        NOT-FOR-US: Rapid7 Insight Platform
 CVE-2024-7341 (A session fixation issue was discovered in the SAML adapters 
provided  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/aa8f0d38b504f2b821af6c161ac28f9882eeab11...1c6b6b093dc954ffb9aaaf4b4586602c3d23876a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/aa8f0d38b504f2b821af6c161ac28f9882eeab11...1c6b6b093dc954ffb9aaaf4b4586602c3d23876a
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to