[Git][security-tracker-team/security-tracker][master] Add CVE-2025-5878/libowasp-esapi-java

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 3 21:30:38 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
61a3d24e by Salvatore Bonaccorso at 2025-07-03T22:30:08+02:00
Add CVE-2025-5878/libowasp-esapi-java

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1138,7 +1138,9 @@ CVE-2025-6855 (A vulnerability, which was classified as critical, has been found
 CVE-2025-6854 (A vulnerability classified as problematic was found in chatchat-space  ...)
 	NOT-FOR-US: Langchain-Chatchat
 CVE-2025-5878 (A vulnerability was found in ESAPI esapi-java-legacy and classified as ...)
-	TODO: check
+	- libowasp-esapi-java <unfixed>
+	NOTE: https://github.com/ESAPI/esapi-java-legacy/commit/f75ac2c2647a81d2cfbdc9c899f8719c240ed512 (esapi-2.7.0.0)
+	NOTE: https://github.com/ESAPI/esapi-java-legacy/commit/e2322914304d9b1c52523ff24be495b7832f6a56 (esapi-2.7.0.0)
 CVE-2025-24292 (A misconfigured query in UniFi Network (v9.1.120 and earlier) could al ...)
 	NOT-FOR-US: Ubiquiti
 CVE-2025-24290 (Multiple Authenticated SQL Injection vulnerabilities found in UISP App ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/61a3d24e7e261079b2e659d87b258460d5e07fae

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/61a3d24e7e261079b2e659d87b258460d5e07fae
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250703/44bfc9a8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list