[Git][security-tracker-team/security-tracker][master] Track fixed verison for mina2 issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 8 06:31:16 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b264a3e6 by Salvatore Bonaccorso at 2026-08-08T07:30:50+02:00
Track fixed verison for mina2 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -53132,7 +53132,7 @@ CVE-2026-47325 (ProjectsAndPrograms school-management-systemuses predictable cre
CVE-2026-47324 (ProjectsAndPrograms school-management-system is vulnerable to Stored C ...)
NOT-FOR-US: ProjectsAndPrograms school-management-system
CVE-2026-47321
- - mina2 <unfixed> (bug #1139162)
+ - mina2 2.2.9-1 (bug #1139162)
[trixie] - mina2 <no-dsa> (Minor issue)
[bookworm] - mina2 <no-dsa> (Minor issue)
[bullseye] - mina2 <postponed> (Minor issue)
@@ -53141,7 +53141,7 @@ CVE-2026-47321
[bullseye] - mina <postponed> (Minor issue)
NOTE: https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj
CVE-2026-47065 (ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter By ...)
- - mina2 <unfixed> (bug #1139162)
+ - mina2 2.2.9-1 (bug #1139162)
[trixie] - mina2 <no-dsa> (Minor issue)
[bookworm] - mina2 <no-dsa> (Minor issue)
[bullseye] - mina2 <postponed> (Minor issue)
@@ -78984,7 +78984,7 @@ CVE-2026-42410 (Improper Neutralization of Input During Web Page Generation ('Cr
CVE-2026-42379 (Insertion of Sensitive Information Into Sent Data vulnerability in WPD ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-41635 (Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, o ...)
- - mina2 <unfixed> (bug #1135167)
+ - mina2 2.2.9-1 (bug #1135167)
[trixie] - mina2 <no-dsa> (Minor issue)
[bookworm] - mina2 <ignored> (Minor issue)
[bullseye] - mina2 <ignored> (Minor issue)
@@ -79005,7 +79005,7 @@ CVE-2026-41463 (ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path tra
CVE-2026-41462 (ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL i ...)
NOT-FOR-US: ProjeQtor
CVE-2026-41409 (The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() ...)
- - mina2 <unfixed> (bug #1135347)
+ - mina2 2.2.9-1 (bug #1135347)
[trixie] - mina2 <no-dsa> (Minor issue)
[bookworm] - mina2 <not-affected> (Incomplete fix for CVE-2024-52046 not applied)
[bullseye] - mina2 <not-affected> (Incomplete fix for CVE-2024-52046 not applied)
@@ -261611,7 +261611,7 @@ CVE-2024-52046 (The ObjectSerializationDecoder in Apache MINA uses Java\u2019s n
- mina <removed>
[bookworm] - mina <no-dsa> (Minor issue)
[bullseye] - mina <postponed> (Minor issue; need specific conditions)
- - mina2 2.2.1-4 (bug #1091530)
+ - mina2 2.2.9-1 (bug #1091530)
[bookworm] - mina2 <no-dsa> (Minor issue)
[bullseye] - mina2 <postponed> (Minor issue; need specific conditions)
NOTE: https://lists.apache.org/thread/4wxktgjpggdbto15d515wdctohb0qmv8
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b264a3e6bb17f6329f9a79e7a5f79ebe1dc57fa5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b264a3e6bb17f6329f9a79e7a5f79ebe1dc57fa5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/c0d5c521/attachment.htm>
More information about the debian-security-tracker-commits
mailing list