Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits: 13590268 by Moritz Muehlenhoff at 2024-06-26T10:48:52+02:00 NFUs - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -125,15 +125,15 @@ CVE-2024-6306 CVE-2024-6305 REJECTED CVE-2024-6303 (Missing authorization in Client-Server API in Conduit <=0.7.0, allowin ...) - TODO: check + NOT-FOR-US: Conduit CVE-2024-6302 (Lack of privilege checking when processing a redaction in Conduit vers ...) - TODO: check + NOT-FOR-US: Conduit CVE-2024-6301 (Lack of validation of origin in federation API in Conduit, allowing an ...) - TODO: check + NOT-FOR-US: Conduit CVE-2024-6300 (Incomplete cleanup when performing redactions in Conduit, allowing an ...) - TODO: check + NOT-FOR-US: Conduit CVE-2024-6299 (Lack of consideration of key expiry when validating signatures in Cond ...) - TODO: check + NOT-FOR-US: Conduit CVE-2024-6257 (HashiCorp\u2019s go-getter library can be coerced into executing Git u ...) - golang-github-hashicorp-go-getter <unfixed> NOTE: https://discuss.hashicorp.com/t/hcsec-2024-13-hashicorp-go-getter-vulnerable-to-code-execution-on-git-update-via-git-config-manipulation/68081 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13590268b3309232c93994e253a9676784d714c1 -- This project does not include diff previews in email notifications. View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13590268b3309232c93994e253a9676784d714c1 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits