[Git][security-tracker-team/security-tracker][master] mojarra n/a
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Aug 13 11:27:05 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b945c192 by Moritz Muehlenhoff at 2026-08-13T12:26:41+02:00
mojarra n/a
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -8677,7 +8677,9 @@ CVE-2026-48834 (Improper Handling of Length Parameter Inconsistency vulnerabilit
CVE-2026-48168 (PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, ...)
NOT-FOR-US: PraisonAI
CVE-2026-46581 (In Eclipse Mojarra versions 2.3 and following, URL handing in `Default ...)
- TODO: check
+ - mojarra <not-affected> (DefaultFaceletFactory added in 2.3)
+ NOTE: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544
+ NOTE: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/160
CVE-2026-44945 (A privilege escalation vulnerability exists in Rancher's impersonation ...)
NOT-FOR-US: Rancher
CVE-2026-39924 (Flarum before 1.8.16 contains an improper session invalidation vulnera ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b945c192ba029eee6459829247a1baa7bca28d23
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b945c192ba029eee6459829247a1baa7bca28d23
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/08896a2c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list