[Git][security-tracker-team/security-tracker][master] Track fixed verison for mina2 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 8 06:31:16 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b264a3e6 by Salvatore Bonaccorso at 2026-08-08T07:30:50+02:00
Track fixed verison for mina2 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -53132,7 +53132,7 @@ CVE-2026-47325 (ProjectsAndPrograms school-management-systemuses predictable cre
 CVE-2026-47324 (ProjectsAndPrograms school-management-system is vulnerable to Stored C ...)
 	NOT-FOR-US: ProjectsAndPrograms school-management-system
 CVE-2026-47321
-	- mina2 <unfixed> (bug #1139162)
+	- mina2 2.2.9-1 (bug #1139162)
 	[trixie] - mina2 <no-dsa> (Minor issue)
 	[bookworm] - mina2 <no-dsa> (Minor issue)
 	[bullseye] - mina2 <postponed> (Minor issue)
@@ -53141,7 +53141,7 @@ CVE-2026-47321
 	[bullseye] - mina <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj
 CVE-2026-47065 (ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter By ...)
-	- mina2 <unfixed> (bug #1139162)
+	- mina2 2.2.9-1 (bug #1139162)
 	[trixie] - mina2 <no-dsa> (Minor issue)
 	[bookworm] - mina2 <no-dsa> (Minor issue)
 	[bullseye] - mina2 <postponed> (Minor issue)
@@ -78984,7 +78984,7 @@ CVE-2026-42410 (Improper Neutralization of Input During Web Page Generation ('Cr
 CVE-2026-42379 (Insertion of Sensitive Information Into Sent Data vulnerability in WPD ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-41635 (Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, o ...)
-	- mina2 <unfixed> (bug #1135167)
+	- mina2 2.2.9-1 (bug #1135167)
 	[trixie] - mina2 <no-dsa> (Minor issue)
 	[bookworm] - mina2 <ignored> (Minor issue)
 	[bullseye] - mina2 <ignored> (Minor issue)
@@ -79005,7 +79005,7 @@ CVE-2026-41463 (ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path tra
 CVE-2026-41462 (ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL i ...)
 	NOT-FOR-US: ProjeQtor
 CVE-2026-41409 (The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() ...)
-	- mina2 <unfixed> (bug #1135347)
+	- mina2 2.2.9-1 (bug #1135347)
 	[trixie] - mina2 <no-dsa> (Minor issue)
 	[bookworm] - mina2 <not-affected> (Incomplete fix for CVE-2024-52046 not applied)
 	[bullseye] - mina2 <not-affected> (Incomplete fix for CVE-2024-52046 not applied)
@@ -261611,7 +261611,7 @@ CVE-2024-52046 (The ObjectSerializationDecoder in Apache MINA uses Java\u2019s n
 	- mina <removed>
 	[bookworm] - mina <no-dsa> (Minor issue)
 	[bullseye] - mina <postponed> (Minor issue; need specific conditions)
-	- mina2 2.2.1-4 (bug #1091530)
+	- mina2 2.2.9-1 (bug #1091530)
 	[bookworm] - mina2 <no-dsa> (Minor issue)
 	[bullseye] - mina2 <postponed> (Minor issue; need specific conditions)
 	NOTE: https://lists.apache.org/thread/4wxktgjpggdbto15d515wdctohb0qmv8



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b264a3e6bb17f6329f9a79e7a5f79ebe1dc57fa5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b264a3e6bb17f6329f9a79e7a5f79ebe1dc57fa5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/c0d5c521/attachment.htm>


More information about the debian-security-tracker-commits mailing list