[Git][security-tracker-team/security-tracker][master] Mark CVE-2025-27407 as no-dsa for bookworm
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 4 20:21:20 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8b91cf52 by Salvatore Bonaccorso at 2025-08-04T21:19:22+02:00
Mark CVE-2025-27407 as no-dsa for bookworm
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -44797,6 +44797,7 @@ CVE-2025-27788 (JSON is a JSON implementation for Ruby. Starting in version 2.10
CVE-2025-27407 (graphql-ruby is a Ruby implementation of GraphQL. Starting in version ...)
{DLA-4263-1}
- ruby-graphql 2.2.17-1 (bug #1100442)
+ [bookworm] - ruby-graphql <no-dsa> (Can be fixed via point release)
NOTE: https://github.com/rmosolgo/graphql-ruby/security/advisories/GHSA-q92j-grw3-h492
NOTE: https://github.com/rmosolgo/graphql-ruby/commit/2d2f4ed1f79472f8eed29c864b039649e1de238f (v1.11.11)
NOTE: https://github.com/rmosolgo/graphql-ruby/commit/28233b16c0eb9d0fb7808f4980e061dc7507c4cd (v1.12.25)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8b91cf52da3ef632909cbfd71fad0dde70f47f94
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8b91cf52da3ef632909cbfd71fad0dde70f47f94
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250804/12095a4b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list