[Git][security-tracker-team/security-tracker][master] Add CVE-2025-27407/ruby-graphql
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Mar 13 20:32:02 GMT 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
299266a5 by Salvatore Bonaccorso at 2025-03-13T21:31:33+01:00
Add CVE-2025-27407/ruby-graphql
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -217,7 +217,15 @@ CVE-2025-27788 (JSON is a JSON implementation for Ruby. Starting in version 2.10
NOTE: Introduced by: https://github.com/ruby/json/commit/5e6cfcf7242a83e79fbc83cb30b3b89373e98b19 (v2.10.0)
NOTE: Fixed by: https://github.com/ruby/json/commit/cf242d89a0523bacd5238a59c77b33411b8c3208 (v2.10.2)
CVE-2025-27407 (graphql-ruby is a Ruby implementation of GraphQL. Starting in version ...)
- TODO: check
+ - ruby-graphql <unfixed>
+ NOTE: https://github.com/rmosolgo/graphql-ruby/security/advisories/GHSA-q92j-grw3-h492
+ NOTE: https://github.com/rmosolgo/graphql-ruby/commit/2d2f4ed1f79472f8eed29c864b039649e1de238f (v1.11.11)
+ NOTE: https://github.com/rmosolgo/graphql-ruby/commit/28233b16c0eb9d0fb7808f4980e061dc7507c4cd (v1.12.25)
+ NOTE: https://github.com/rmosolgo/graphql-ruby/commit/6eca16b9fa553aa957099a30dbde64ddcdac52ca (v1.13.24)
+ NOTE: https://github.com/rmosolgo/graphql-ruby/commit/d0963289e0dab4ea893bbecf12bb7d89294957bb (v2.0.32)
+ NOTE: https://github.com/rmosolgo/graphql-ruby/commit/d1117ae0361d9ed67e0795b07f5c3e98e62f3c7c (v2.1.14)
+ NOTE: https://github.com/rmosolgo/graphql-ruby/commit/5c5a7b9a9bdce143be048074aea50edb7bb747be (v2.2.17)
+ NOTE: https://github.com/rmosolgo/graphql-ruby/commit/e3b33ace05391da2871c75ab4d3b66e29133b367 (v2.3.21)
CVE-2025-27017 (Apache NiFi 1.13.0 through 2.2.0 includes the username and password us ...)
NOT-FOR-US: Apache NiFi
CVE-2025-26260 (Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.sv ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/299266a5beb40b13560c312c3aebbabc95f95b8d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/299266a5beb40b13560c312c3aebbabc95f95b8d
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250313/f24811d4/attachment.htm>
More information about the debian-security-tracker-commits
mailing list