[Git][security-tracker-team/security-tracker][master] Add references for RT upstream commits
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Oct 22 21:34:22 BST 2025
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1532b23f by Salvatore Bonaccorso at 2025-10-22T22:33:55+02:00
Add references for RT upstream commits
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,12 @@
CVE-2025-9158
- request-tracker5 <unfixed>
[bookworm] - request-tracker5 <not-affected> (Vulnerable code introduced later)
+ NOTE: Fixed by: https://github.com/bestpractical/rt/commit/04b5694e6cd150492aa51b8edaba75f5997ea40c (rt-5.0.9)
CVE-2025-61873
- request-tracker5 <unfixed>
- request-tracker4 <unfixed>
+ NOTE: Fixed by: https://github.com/bestpractical/rt/commit/cade8b90c696e8c08438be2cb469a78342b5cb0f (rt-5.0.9)
+ NOTE: Fixed by: https://github.com/bestpractical/rt/commit/2f5798fee46155a947f57dfafed2542f03906dd7 (rt-4.4.9)
CVE-2025-8848 (A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML ...)
TODO: check
CVE-2025-6833 (The All in One Time Clock Lite \u2013 Tracking Employee Time Has Never ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1532b23fb73a55b6793576bd7d08d8566468ed47
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1532b23fb73a55b6793576bd7d08d8566468ed47
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251022/b8325275/attachment.htm>
More information about the debian-security-tracker-commits
mailing list