[Git][security-tracker-team/security-tracker][master] Cleanup several CVEs which got rejected and were NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 05:50:03 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a1840a0c by Salvatore Bonaccorso at 2026-08-14T06:49:33+02:00
Cleanup several CVEs which got rejected and were NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -160139,7 +160139,6 @@ CVE-2025-64076 (Multiple vulnerabilities exist in cbor2 through version 5.7.0 in
 	NOTE: Debian builds src:cbor2 with CBOR2_BUILD_C_EXTENSION=0 (not building C extensions)
 CVE-2025-63994
 	REJECTED
-	NOT-FOR-US: RichFilemanager
 CVE-2025-63955 (A Cross-Site Request Forgery (CSRF) vulnerability in the manage-studen ...)
 	NOT-FOR-US: PHPGurukul
 CVE-2025-63892 (A vulnerability was determined in SourceCodester Student Grades Manage ...)
@@ -241376,7 +241375,6 @@ CVE-2024-8061 (In version 3.23.0 of aimhubio/aim, certain methods that request d
 	NOT-FOR-US: aimhubio/aim
 CVE-2024-8060
 	REJECTED
-	NOT-FOR-US: OpenWebUI
 CVE-2024-8057 (In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a ...)
 	NOT-FOR-US: danswer-ai/danswer
 CVE-2024-8055 (Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in  ...)
@@ -241407,7 +241405,6 @@ CVE-2024-7999
 	REJECTED
 CVE-2024-7990
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7983 (In version 0.3.8 of open-webui, an endpoint for converting markdown to ...)
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7959
@@ -241458,13 +241455,10 @@ CVE-2024-7058 (A vulnerability in the sanitize_path function in parisneo/lollms-
 	NOT-FOR-US: parisneo/lollms-webui
 CVE-2024-7053
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7046
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7045
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7044 (A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat f ...)
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7043 (An improper access control vulnerability in open-webui/open-webui v0.3 ...)
@@ -241475,7 +241469,6 @@ CVE-2024-7039
 	REJECTED
 CVE-2024-7036
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7035 (In version v0.3.8 of open-webui/open-webui, sensitive actions such as  ...)
 	NOT-FOR-US: open-webui/open-webui
 CVE-2024-7034
@@ -241614,10 +241607,8 @@ CVE-2024-12580 (A vulnerability in danny-avila/librechat prior to version 0.7.6
 	NOT-FOR-US: danny-avila/librechat
 CVE-2024-12537
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-12534
 	REJECTED
-	NOT-FOR-US: open-webui/open-webui
 CVE-2024-12450 (In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `do ...)
 	NOT-FOR-US: infiniflow/ragflow
 CVE-2024-12433 (A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remo ...)
@@ -292030,7 +292021,6 @@ CVE-2024-7038
 	REJECTED
 CVE-2024-7037
 	REJECTED
-	NOT-FOR-US: open-webui
 CVE-2024-5968 (The Photo Gallery by 10Web  WordPress plugin before 1.8.28 does not pr ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-47951 (In JetBrains TeamCity before 2024.07.3 stored XSS was possible via ser ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a1840a0c1566ad046fa5984e2b26e6806c11f444

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a1840a0c1566ad046fa5984e2b26e6806c11f444
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/8adf0804/attachment.htm>


More information about the debian-security-tracker-commits mailing list