[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 21:26:24 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
01871298 by Salvatore Bonaccorso at 2026-08-14T22:25:55+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -88,7 +88,7 @@ CVE-2026-72811 (SiYuan versions <= v3.7.2 contain a SQL injection vulnerability
 CVE-2026-72810 (SiYuan versions before v3.7.4 contain a publish-boundary bypass vulner ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-69101 (Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vu ...)
-	TODO: check
+	NOT-FOR-US: Datavane TIS
 CVE-2026-66272 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain  ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-66271 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain  ...)
@@ -2372,7 +2372,7 @@ CVE-2026-71407 (A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerabil
 CVE-2026-70560 (Ultimate POS (Stock Management & Point of Sale) contains a stored cros ...)
 	NOT-FOR-US: Ultimate POS (Stock Management & Point of Sale)
 CVE-2026-70547 (An authenticated user without repository read permission may access pa ...)
-	TODO: check
+	NOT-FOR-US: jfrog artifactory
 CVE-2026-70468 (A authentication bypass using an alternate path or channel vulnerabili ...)
 	NOT-FOR-US: Fortinet
 CVE-2026-70467 (A server-side request forgery (ssrf) vulnerability in Fortinet FortiSI ...)
@@ -2382,29 +2382,29 @@ CVE-2026-70466 (A incomplete list of disallowed inputs vulnerability in Fortinet
 CVE-2026-70465 (A buffer copy without checking size of input ('classic buffer overflow ...)
 	NOT-FOR-US: Fortinet
 CVE-2026-69107 (An unauthenticated user may access restricted artifacts in JFrog Artif ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-69106 (A low-privileged user may poison cached artifact metadata under specif ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-69105 (An unauthenticated attacker may cause untrusted package content to be  ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-68760 (An unauthenticated user may bypass authentication under specific cache ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-68759 (A holder of a valid integration credential may impersonate other users ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-68758 (A low-privileged authenticated user may access restricted support info ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-68757 (A user with access to a valid SAML response may impersonate another us ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-68756 (A party with write access to stored session data may affect JFrog Arti ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-68755 (A bundle writer may create misleading release promotion information un ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-68754 (A repository publisher without delete permission may modify protected  ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-68753 (An unauthenticated user may access restricted Artifactory content when ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-68752 (A Project Resource Manager may gain broader administrative privileges  ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-67587 (Apache Airflow's Task SDK rebuilt a `Callback` object from serialized  ...)
 	TODO: check
 CVE-2026-67287 (Joomla Extension - joomshaper.com - Unauthenticated comment creation i ...)
@@ -3711,13 +3711,13 @@ CVE-2026-69117 (NetBox 4.5.8 contains an ORM injection vulnerability that allows
 CVE-2026-69115 (OpenIM Server v3.8.3 contains a missing authorization vulnerability th ...)
 	NOT-FOR-US: OpenIM Server
 CVE-2026-69113 (Cap v0.3.1 contains a broken access control vulnerability in the POST  ...)
-	TODO: check
+	NOT-FOR-US: Cap
 CVE-2026-69109 (A vulnerability has been identified in Siemens License Server (SLS) (A ...)
 	NOT-FOR-US: Siemens
 CVE-2026-69108 (A vulnerability has been identified in Siemens License Server (SLS) (A ...)
 	NOT-FOR-US: Siemens
 CVE-2026-69102 (MaxKey contains an unauthorized access vulnerability due to a hard-cod ...)
-	TODO: check
+	NOT-FOR-US: MaxKey
 CVE-2026-68821 (Improper privilege management in Windows Package Manager allows an aut ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-68820 (Use after free in Windows Ancillary Function Driver for WinSock allows ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/018712980fbdc38c7546e0c99ec13f10c91004b1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/018712980fbdc38c7546e0c99ec13f10c91004b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/0fa8ddc1/attachment.htm>


More information about the debian-security-tracker-commits mailing list