Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits: 7ee39762 by Moritz Muehlenhoff at 2024-11-13T21:02:31+01:00 triage older issues - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -11997,7 +11997,7 @@ CVE-2024-47561 (Schema parsing in the Java SDK of Apache Avro 1.11.3 and previou NOT-FOR-US: Apache Avro CVE-2024-47554 (Uncontrolled Resource Consumption vulnerability in Apache Commons IO. ...) - commons-io 2.16.0-1 - [bookworm] - commons-io <no-dsa> (Minor issue) + [bookworm] - commons-io <ignored> (Minor issue) [bullseye] - commons-io <postponed> (Minor issue; can be fixed in next update) NOTE: https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1 CVE-2024-45872 (Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x41 ...) @@ -68821,7 +68821,7 @@ CVE-2024-21504 (Versions of the package livewire/livewire from 3.3.5 and before NOT-FOR-US: livewire CVE-2024-21503 (Versions of the package black before 24.3.0 are vulnerable to Regular ...) - black 24.4.0-1 (bug #1067177) - [bookworm] - black <no-dsa> (Minor issue) + [bookworm] - black <ignored> (Minor issue) [bullseye] - black <no-dsa> (Minor issue) [buster] - black <postponed> (Minor issue; can be fixed in next update) NOTE: https://security.snyk.io/vuln/SNYK-PYTHON-BLACK-6256273 @@ -79025,7 +79025,7 @@ CVE-2024-24822 (Pimcore's Admin Classic Bundle provides a backend user interface NOT-FOR-US: Pimcore's Admin Classic Bundle CVE-2024-24816 (CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...) - ckeditor <unfixed> (bug #1063536) - [bookworm] - ckeditor <no-dsa> (Minor issue) + [bookworm] - ckeditor <ignored> (Minor issue, only affects shipped example files) [bullseye] - ckeditor <no-dsa> (Minor issue) [buster] - ckeditor <no-dsa> (Minor issue) - ckeditor3 <unfixed> (bug #1063537; unimportant) @@ -79034,7 +79034,7 @@ CVE-2024-24816 (CKEditor4 is an open source what-you-see-is-what-you-get HTML ed [buster] - ckeditor3 <end-of-life> (No longer supported in LTS) NOTE: https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-mw2c-vx6j-mg76 NOTE: https://github.com/ckeditor/ckeditor4/commit/7518202f0f228ee5549a36ecb7cb880b06ea5add (4.24.0-lts) - NOTE: The samples are not shipped in ckedito3 + NOTE: The samples are not shipped in ckeditor3 CVE-2024-24815 (CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...) - ckeditor <unfixed> (bug #1063536) [bookworm] - ckeditor <no-dsa> (Minor issue) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ee39762bd4ba3df2e3220cc73a95b5928082e79 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ee39762bd4ba3df2e3220cc73a95b5928082e79 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits