[Git][security-tracker-team/security-tracker][master] Cleanup several CVEs which got rejected and were NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 05:50:03 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a1840a0c by Salvatore Bonaccorso at 2026-08-14T06:49:33+02:00
Cleanup several CVEs which got rejected and were NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -160139,7 +160139,6 @@ CVE-2025-64076 (Multiple vulnerabilities exist in cbor2 through version 5.7.0 in
NOTE: Debian builds src:cbor2 with CBOR2_BUILD_C_EXTENSION=0 (not building C extensions)
CVE-2025-63994
REJECTED
- NOT-FOR-US: RichFilemanager
CVE-2025-63955 (A Cross-Site Request Forgery (CSRF) vulnerability in the manage-studen ...)
NOT-FOR-US: PHPGurukul
CVE-2025-63892 (A vulnerability was determined in SourceCodester Student Grades Manage ...)
@@ -241376,7 +241375,6 @@ CVE-2024-8061 (In version 3.23.0 of aimhubio/aim, certain methods that request d
NOT-FOR-US: aimhubio/aim
CVE-2024-8060
REJECTED
- NOT-FOR-US: OpenWebUI
CVE-2024-8057 (In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a ...)
NOT-FOR-US: danswer-ai/danswer
CVE-2024-8055 (Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in ...)
@@ -241407,7 +241405,6 @@ CVE-2024-7999
REJECTED
CVE-2024-7990
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-7983 (In version 0.3.8 of open-webui, an endpoint for converting markdown to ...)
NOT-FOR-US: open-webui/open-webui
CVE-2024-7959
@@ -241458,13 +241455,10 @@ CVE-2024-7058 (A vulnerability in the sanitize_path function in parisneo/lollms-
NOT-FOR-US: parisneo/lollms-webui
CVE-2024-7053
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-7046
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-7045
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-7044 (A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat f ...)
NOT-FOR-US: open-webui/open-webui
CVE-2024-7043 (An improper access control vulnerability in open-webui/open-webui v0.3 ...)
@@ -241475,7 +241469,6 @@ CVE-2024-7039
REJECTED
CVE-2024-7036
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-7035 (In version v0.3.8 of open-webui/open-webui, sensitive actions such as ...)
NOT-FOR-US: open-webui/open-webui
CVE-2024-7034
@@ -241614,10 +241607,8 @@ CVE-2024-12580 (A vulnerability in danny-avila/librechat prior to version 0.7.6
NOT-FOR-US: danny-avila/librechat
CVE-2024-12537
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-12534
REJECTED
- NOT-FOR-US: open-webui/open-webui
CVE-2024-12450 (In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `do ...)
NOT-FOR-US: infiniflow/ragflow
CVE-2024-12433 (A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remo ...)
@@ -292030,7 +292021,6 @@ CVE-2024-7038
REJECTED
CVE-2024-7037
REJECTED
- NOT-FOR-US: open-webui
CVE-2024-5968 (The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not pr ...)
NOT-FOR-US: WordPress plugin
CVE-2024-47951 (In JetBrains TeamCity before 2024.07.3 stored XSS was possible via ser ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a1840a0c1566ad046fa5984e2b26e6806c11f444
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a1840a0c1566ad046fa5984e2b26e6806c11f444
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/8adf0804/attachment.htm>
More information about the debian-security-tracker-commits
mailing list