Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits: 73b0bf02 by Moritz Muehlenhoff at 2025-01-22T11:14:30+01:00 new lemonldap-ng issue - - - - - 2 changed files: - data/CVE/list - data/next-point-update.txt Changes: ===================================== data/CVE/list ===================================== @@ -1,3 +1,11 @@ +CVE-2024-52948 [CSRF on 2FA registration] + - lemonldap-ng 2.20.2+ds-1 + [bookworm] - lemonldap-ng <no-dsa> (Will be fixed via point update) + NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3258 + NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/0e69ee17ee7e78569a6f7a3c859105e958d374d4 + NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/d65bd9cb8e9a620f71214d87e937747d7b415999 + NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/9923ed4479b3c71549f9a9660f77dc03331eac30 + NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/dfe9ddc40de982a33fbff42a143ccd1b786de775 CVE-2025-0509 - openjdk-8 <not-affected> (Specific to MacOS packaging of Oracle Java) CVE-2025-23237 (Improper neutralization of special elements used in an OS command ('OS ...) ===================================== data/next-point-update.txt ===================================== @@ -66,3 +66,5 @@ CVE-2021-33645 [bookworm] - libtar 1.2.20-8+deb12u1 CVE-2021-33646 [bookworm] - libtar 1.2.20-8+deb12u1 +CVE-2024-52948 + [bookworm] - lemonldap-ng 2.16.1+ds-deb12u5 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73b0bf02a00db89c7f96e1d3e29743b36309c2b4 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73b0bf02a00db89c7f96e1d3e29743b36309c2b4 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits