[Git][security-tracker-team/security-tracker][master] new ruby-sidekiq issue

2024-04-27 Thread Moritz Muehlenhoff (@jmm)


Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8e1c309c by Moritz Muehlenhoff at 2024-04-27T20:35:34+02:00
new ruby-sidekiq issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=
data/CVE/list
=
@@ -19,7 +19,9 @@ CVE-2024-3051 (Malformed Device Reset Locally command classes 
can be sent to tem
 CVE-2024-3034 (The BackUpWordPress plugin for WordPress is vulnerable to 
Directory Tr ...)
NOT-FOR-US: WordPress plugin
 CVE-2024-32887 (Sidekiq is simple, efficient background processing for Ruby. 
Sidekiq i ...)
-   TODO: check
+   - ruby-sidekiq 
+   NOTE: 
https://github.com/sidekiq/sidekiq/commit/30786e082c70349ab27ffa9eccc42fb0c696164d
 (v7.2.4)
+   NOTE: 
https://github.com/sidekiq/sidekiq/security/advisories/GHSA-q655-3pj8-9fxq
 CVE-2024-32883 (MCUboot is a secure bootloader for 32-bits microcontrollers. 
MCUboot u ...)
NOT-FOR-US: mcuboot
 CVE-2024-32881 (Danswer is the AI Assistant connected to company's docs, apps, 
and peo ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e1c309c51ee60f3504ea4aeae9fadf457400395

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e1c309c51ee60f3504ea4aeae9fadf457400395
You're receiving this email because of your account on salsa.debian.org.


___
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits


[Git][security-tracker-team/security-tracker][master] new ruby-sidekiq issue

2023-04-06 Thread Moritz Muehlenhoff (@jmm)


Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2366a70a by Moritz Mühlenhoff at 2023-04-06T17:42:29+02:00
new ruby-sidekiq issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=
data/CVE/list
=
@@ -122,7 +122,9 @@ CVE-2023-29384
 CVE-2023-1893
RESERVED
 CVE-2023-1892 (Cross-site Scripting (XSS) - Reflected in GitHub repository 
sidekiq/si ...)
-   TODO: check
+   - ruby-sidekiq 
+   NOTE: https://huntr.dev/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777
+   NOTE: 
https://github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214
 CVE-2023-1891
RESERVED
 CVE-2023-1890



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2366a70a31e3aa1c41f4cc2387344add1ea4db52

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2366a70a31e3aa1c41f4cc2387344add1ea4db52
You're receiving this email because of your account on salsa.debian.org.


___
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits