[Git][security-tracker-team/security-tracker][master] 2 commits: Process one NFU
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Nov 5 21:21:10 GMT 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6e13cbf3 by Salvatore Bonaccorso at 2025-11-05T22:20:09+01:00
Process one NFU
- - - - -
a3c4b7b3 by Salvatore Bonaccorso at 2025-11-05T22:20:31+01:00
auto-nfu: Add one more covered product for Apache CNA rule
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -33,7 +33,7 @@ CVE-2025-5770 (A reflected cross-site scripting (XSS) vulnerability exists in th
CVE-2025-59716 (ownCloud Guests before 0.12.5 allows unauthenticated user enumeration ...)
TODO: check
CVE-2025-58337 (An attacker with a valid read-only account can bypass Doris MCP Server ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2025-57244 (OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scr ...)
NOT-FOR-US: OpenKM
CVE-2025-57130 (An Incorrect Access Control vulnerability in the user management compo ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -286,6 +286,7 @@
- product: Apache APISIX
- product: Apache CXF
- product: Apache DolphinScheduler
+ - product: Apache Doris-MCP-Server
- product: Apache Fory
- product: Apache Geode
- product: Apache HertzBeat (incubating)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d8514d780226d743fba285ef3389230dfc95e961...a3c4b7b3a7dbaf40413aa720cc42d544dc846956
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d8514d780226d743fba285ef3389230dfc95e961...a3c4b7b3a7dbaf40413aa720cc42d544dc846956
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251105/1e4ba09a/attachment.htm>
More information about the debian-security-tracker-commits
mailing list