[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 21:26:24 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
01871298 by Salvatore Bonaccorso at 2026-08-14T22:25:55+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -88,7 +88,7 @@ CVE-2026-72811 (SiYuan versions <= v3.7.2 contain a SQL injection vulnerability
CVE-2026-72810 (SiYuan versions before v3.7.4 contain a publish-boundary bypass vulner ...)
NOT-FOR-US: SiYuan
CVE-2026-69101 (Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vu ...)
- TODO: check
+ NOT-FOR-US: Datavane TIS
CVE-2026-66272 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
NOT-FOR-US: Dell / EMC
CVE-2026-66271 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
@@ -2372,7 +2372,7 @@ CVE-2026-71407 (A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerabil
CVE-2026-70560 (Ultimate POS (Stock Management & Point of Sale) contains a stored cros ...)
NOT-FOR-US: Ultimate POS (Stock Management & Point of Sale)
CVE-2026-70547 (An authenticated user without repository read permission may access pa ...)
- TODO: check
+ NOT-FOR-US: jfrog artifactory
CVE-2026-70468 (A authentication bypass using an alternate path or channel vulnerabili ...)
NOT-FOR-US: Fortinet
CVE-2026-70467 (A server-side request forgery (ssrf) vulnerability in Fortinet FortiSI ...)
@@ -2382,29 +2382,29 @@ CVE-2026-70466 (A incomplete list of disallowed inputs vulnerability in Fortinet
CVE-2026-70465 (A buffer copy without checking size of input ('classic buffer overflow ...)
NOT-FOR-US: Fortinet
CVE-2026-69107 (An unauthenticated user may access restricted artifacts in JFrog Artif ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-69106 (A low-privileged user may poison cached artifact metadata under specif ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-69105 (An unauthenticated attacker may cause untrusted package content to be ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68760 (An unauthenticated user may bypass authentication under specific cache ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68759 (A holder of a valid integration credential may impersonate other users ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68758 (A low-privileged authenticated user may access restricted support info ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68757 (A user with access to a valid SAML response may impersonate another us ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68756 (A party with write access to stored session data may affect JFrog Arti ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68755 (A bundle writer may create misleading release promotion information un ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68754 (A repository publisher without delete permission may modify protected ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68753 (An unauthenticated user may access restricted Artifactory content when ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-68752 (A Project Resource Manager may gain broader administrative privileges ...)
- TODO: check
+ NOT-FOR-US: JFrog Artifactory
CVE-2026-67587 (Apache Airflow's Task SDK rebuilt a `Callback` object from serialized ...)
TODO: check
CVE-2026-67287 (Joomla Extension - joomshaper.com - Unauthenticated comment creation i ...)
@@ -3711,13 +3711,13 @@ CVE-2026-69117 (NetBox 4.5.8 contains an ORM injection vulnerability that allows
CVE-2026-69115 (OpenIM Server v3.8.3 contains a missing authorization vulnerability th ...)
NOT-FOR-US: OpenIM Server
CVE-2026-69113 (Cap v0.3.1 contains a broken access control vulnerability in the POST ...)
- TODO: check
+ NOT-FOR-US: Cap
CVE-2026-69109 (A vulnerability has been identified in Siemens License Server (SLS) (A ...)
NOT-FOR-US: Siemens
CVE-2026-69108 (A vulnerability has been identified in Siemens License Server (SLS) (A ...)
NOT-FOR-US: Siemens
CVE-2026-69102 (MaxKey contains an unauthorized access vulnerability due to a hard-cod ...)
- TODO: check
+ NOT-FOR-US: MaxKey
CVE-2026-68821 (Improper privilege management in Windows Package Manager allows an aut ...)
NOT-FOR-US: Microsoft
CVE-2026-68820 (Use after free in Windows Ancillary Function Driver for WinSock allows ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/018712980fbdc38c7546e0c99ec13f10c91004b1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/018712980fbdc38c7546e0c99ec13f10c91004b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/0fa8ddc1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list