[Git][security-tracker-team/security-tracker][master] auto-nfu: Extend Mediawiki rule
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Oct 22 21:51:58 BST 2025
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7a7280a9 by Moritz Muehlenhoff at 2025-10-22T22:51:33+02:00
auto-nfu: Extend Mediawiki rule
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -13,7 +13,7 @@ CVE-2025-8848 (A vulnerability in danny-avila/librechat version 0.7.9 allows for
CVE-2025-6833 (The All in One Time Clock Lite \u2013 Tracking Employee Time Has Never ...)
NOT-FOR-US: WordPress plugin
CVE-2025-62659 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
CVE-2025-62611 (aiomysql is a library for accessing a MySQL database from the asyncio. ...)
TODO: check
CVE-2025-62610 (Hono is a Web application framework that provides support for any Java ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -544,6 +544,7 @@
allOf:
- cna: wikimedia-foundation
- anyOf:
+ - product: MediaWiki CookieConsent extension
- product: MediaWiki GlobalBlocking extension
- product: MediaWiki PageForms extension
- product: MediaWiki WatchAnalytics extension
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a7280a923d85c9e101e29eae202a3b5e6bdc1f6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a7280a923d85c9e101e29eae202a3b5e6bdc1f6
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251022/76e80ad9/attachment.htm>
More information about the debian-security-tracker-commits
mailing list