Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
6826509d by Moritz Muehlenhoff at 2024-12-13T09:39:24+01:00
new gitlab issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -60,7 +60,7 @@ CVE-2024-8647 (An issue was discovered in GitLab affecting 
all versions starting
 CVE-2024-8233 (An issue has been discovered in GitLab CE/EE affecting all 
versions fr ...)
        - gitlab <unfixed>
 CVE-2024-8179 (An issue has been discovered in GitLab CE/EE affecting all 
versions fr ...)
-       TODO: check
+       - gitlab <unfixed>
 CVE-2024-55888 (Hush Line is an open-source whistleblower management system. 
Starting  ...)
        NOT-FOR-US: Hush Line
 CVE-2024-55886 (OpenSearch Data Prepper is a component of the OpenSearch 
project that  ...)
@@ -175,13 +175,13 @@ CVE-2024-21575 (ComfyUI-Impact-Pack is vulnerable to Path 
Traversal. The issue s
 CVE-2024-21574 (The issue stems from a missing validation of the pip field in 
a POST r ...)
        NOT-FOR-US: ComfyUI-Impact-Pack
 CVE-2024-12570 (An issue has been discovered in GitLab CE/EE affecting all 
versions st ...)
-       TODO: check
+       - gitlab <unfixed>
 CVE-2024-12401 (A flaw was found in the cert-manager package. This flaw allows 
an atta ...)
        NOT-FOR-US: Open Shift
 CVE-2024-12333 (The Woodmart theme for WordPress is vulnerable to arbitrary 
shortcode  ...)
        NOT-FOR-US: WordPress theme
 CVE-2024-12292 (An issue was discovered in GitLab CE/EE affecting all versions 
startin ...)
-       TODO: check
+       - gitlab <unfixed>
 CVE-2024-12271 (The 360 Javascript Viewer plugin for WordPress is vulnerable 
to Stored ...)
        NOT-FOR-US: WordPress plugin
 CVE-2024-12160 (The Seraphinite Bulk Discounts for WooCommerce plugin for 
WordPress is ...)
@@ -189,9 +189,9 @@ CVE-2024-12160 (The Seraphinite Bulk Discounts for 
WooCommerce plugin for WordPr
 CVE-2024-11760 (The Currency Converter Widget \u26a1 PRO plugin for WordPress 
is vulne ...)
        NOT-FOR-US: WordPress plugin
 CVE-2024-11274 (An issue was discovered in GitLab CE/EE affecting all versions 
startin ...)
-       TODO: check
+       - gitlab <unfixed>
 CVE-2024-10043 (An issue has been discovered in GitLab EE affecting all 
versions start ...)
-       TODO: check
+       - gitlab <not-affected> (Specific to EE)
 CVE-2024-55633 (Improper Authorization vulnerability in Apache Superset. On 
Postgres a ...)
        NOT-FOR-US: Apache Superset
 CVE-2024-9881 (The LearnPress  WordPress plugin before 4.2.7.2 does not 
sanitise and  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6826509d490110112cb6f12ce80c0af5b89fdda5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6826509d490110112cb6f12ce80c0af5b89fdda5
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to