[Git][security-tracker-team/security-tracker][master] three icinga2 issues CVEfied
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 10 16:11:10 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7d03912d by Moritz Muehlenhoff at 2026-08-10T14:23:56+02:00
three icinga2 issues CVEfied
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -31708,13 +31708,13 @@ CVE-2026-10089 (The Insert Pages plugin for WordPress is vulnerable to Stored Cr
NOT-FOR-US: WordPress plugin
CVE-2026-10077 (The yootheme WordPress theme before 5.0.35 does not prevent its bundle ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-XXXX [GHSA-jgqj-x5j9-vgcm: Icinga 2 DSL Injection via Unescaped Import Template Name]
+CVE-2026-61552 [GHSA-jgqj-x5j9-vgcm: Icinga 2 DSL Injection via Unescaped Import Template Name]
- icinga2 2.16.2-1
NOTE: https://github.com/Icinga/icinga2/security/advisories/GHSA-jgqj-x5j9-vgcm
NOTE: https://icinga.com/blog/icinga2-security-release-v2-16-2/
NOTE: Fixed by: https://github.com/Icinga/icinga2/commit/af4b36e6464b9b214bed270a53d6474cf91eb441 (v2.16.2)
NOTE: Fixed by: https://github.com/Icinga/icinga2/commit/eec0d90e8303376fe772b3e4a04e3b064a44cf30 (v2.14.9)
-CVE-2026-XXXX [GHSA-wh38-wg57-5w7g: Stack overflow via deeply nested JSON objects]
+CVE-2026-61551 [GHSA-wh38-wg57-5w7g: Stack overflow via deeply nested JSON objects]
- icinga2 2.16.2-1
NOTE: https://github.com/Icinga/icinga2/security/advisories/GHSA-wh38-wg57-5w7g
NOTE: https://icinga.com/blog/icinga2-security-release-v2-16-2/
@@ -31734,7 +31734,7 @@ CVE-2026-XXXX [GHSA-wh38-wg57-5w7g: Stack overflow via deeply nested JSON object
NOTE: Fixed by: https://github.com/Icinga/icinga2/commit/69093a8ae0f09bbef8f589cbc67f131f167e5aa3 (v2.14.9)
NOTE: Fixed by: https://github.com/Icinga/icinga2/commit/221d3fa9a66c248bc478220e4a73e1be661dd449 (v2.14.9)
NOTE: Fixed by: https://github.com/Icinga/icinga2/commit/e23a3eb42d791f27c1073b56769800fe12156425 (v2.14.9)
-CVE-2026-XXXX [GHSA-vj39-ww8j-vvx5: Improper access control for JSON-RPC update certificate messages]
+CVE-2026-61550 [GHSA-vj39-ww8j-vvx5: Improper access control for JSON-RPC update certificate messages]
- icinga2 2.16.2-1
NOTE: https://github.com/Icinga/icinga2/security/advisories/GHSA-vj39-ww8j-vvx5
NOTE: https://icinga.com/blog/icinga2-security-release-v2-16-2/
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d03912dab4758dbef79c8f4b3b422b2355f9942
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d03912dab4758dbef79c8f4b3b422b2355f9942
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/1ae2865c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list