[Git][security-tracker-team/security-tracker][master] Add CVE-2025-44203/hoteldruid

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jun 20 21:41:20 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e782f605 by Salvatore Bonaccorso at 2025-06-20T22:40:58+02:00
Add CVE-2025-44203/hoteldruid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -299,7 +299,8 @@ CVE-2025-45331 (brplot v420.69.1 contains a Null Pointer Dereference (NPD) vulne
 CVE-2025-44635 (There are multiple unauthorized remote command execution vulnerabiliti ...)
 	NOT-FOR-US: H3C
 CVE-2025-44203 (In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose S ...)
-	TODO: check
+	- hoteldruid <unfixed>
+	NOTE: https://github.com/IvanT7D3/CVE-2025-44203
 CVE-2025-3319 (IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to ...)
 	NOT-FOR-US: IBM
 CVE-2025-3228 (Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10. ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e782f605686341e20f7142a0063458e138448243

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e782f605686341e20f7142a0063458e138448243
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250620/97877245/attachment.htm>


More information about the debian-security-tracker-commits mailing list