[Git][security-tracker-team/security-tracker][master] 2 commits: Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Apr 7 05:03:28 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
464c7f21 by Salvatore Bonaccorso at 2025-04-07T05:51:58+02:00
Process some NFUs
- - - - -
dcedda7f by Salvatore Bonaccorso at 2025-04-07T06:02:22+02:00
Track fixed version for CVE-2025-27407/ruby-graphql
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,11 +3,11 @@ CVE-2025-3318 (A vulnerability classified as critical was found in Kenj_Frog \u8
CVE-2025-3317 (A vulnerability classified as problematic has been found in fumiao ope ...)
TODO: check
CVE-2025-3316 (A vulnerability was found in PHPGurukul Men Salon Management System 1. ...)
- TODO: check
+ NOT-FOR-US: PHPGurukul
CVE-2025-3315 (A vulnerability was found in SourceCodester Apartment Visitor Manageme ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2025-3314 (A vulnerability has been found in SourceCodester Apartment Visitor Man ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2025-32013 (LNbits is a Lightning wallet and accounts system. A Server-Side Reques ...)
TODO: check
CVE-2025-31492 (mod_auth_openidc is an OpenID Certified authentication and authorizati ...)
@@ -8198,7 +8198,7 @@ CVE-2025-27788 (JSON is a JSON implementation for Ruby. Starting in version 2.10
NOTE: Introduced by: https://github.com/ruby/json/commit/5e6cfcf7242a83e79fbc83cb30b3b89373e98b19 (v2.10.0)
NOTE: Fixed by: https://github.com/ruby/json/commit/cf242d89a0523bacd5238a59c77b33411b8c3208 (v2.10.2)
CVE-2025-27407 (graphql-ruby is a Ruby implementation of GraphQL. Starting in version ...)
- - ruby-graphql <unfixed> (bug #1100442)
+ - ruby-graphql 2.2.17-1 (bug #1100442)
NOTE: https://github.com/rmosolgo/graphql-ruby/security/advisories/GHSA-q92j-grw3-h492
NOTE: https://github.com/rmosolgo/graphql-ruby/commit/2d2f4ed1f79472f8eed29c864b039649e1de238f (v1.11.11)
NOTE: https://github.com/rmosolgo/graphql-ruby/commit/28233b16c0eb9d0fb7808f4980e061dc7507c4cd (v1.12.25)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c07351009dec41a0b62a6d6b28075e78a245e9fe...dcedda7fa55f6035703d5b781771eeef10eea276
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c07351009dec41a0b62a6d6b28075e78a245e9fe...dcedda7fa55f6035703d5b781771eeef10eea276
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250407/2264709a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list