[Git][security-tracker-team/security-tracker][master] Add references for RT upstream commits

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Oct 22 21:34:22 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1532b23f by Salvatore Bonaccorso at 2025-10-22T22:33:55+02:00
Add references for RT upstream commits

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,12 @@
 CVE-2025-9158
 	- request-tracker5 <unfixed>
 	[bookworm] - request-tracker5 <not-affected> (Vulnerable code introduced later)
+	NOTE: Fixed by: https://github.com/bestpractical/rt/commit/04b5694e6cd150492aa51b8edaba75f5997ea40c (rt-5.0.9)
 CVE-2025-61873
 	- request-tracker5 <unfixed>
 	- request-tracker4 <unfixed>
+	NOTE: Fixed by: https://github.com/bestpractical/rt/commit/cade8b90c696e8c08438be2cb469a78342b5cb0f (rt-5.0.9)
+	NOTE: Fixed by: https://github.com/bestpractical/rt/commit/2f5798fee46155a947f57dfafed2542f03906dd7 (rt-4.4.9)
 CVE-2025-8848 (A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML ...)
 	TODO: check
 CVE-2025-6833 (The All in One Time Clock Lite \u2013 Tracking Employee Time Has Never ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1532b23fb73a55b6793576bd7d08d8566468ed47

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1532b23fb73a55b6793576bd7d08d8566468ed47
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251022/b8325275/attachment.htm>


More information about the debian-security-tracker-commits mailing list