[Git][security-tracker-team/security-tracker][master] track misp ITP
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Aug 19 16:15:25 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fbb044df by Moritz Muehlenhoff at 2026-08-19T17:13:11+02:00
track misp ITP
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -12597,23 +12597,23 @@ CVE-2026-73211 (PeerTube is an ActivityPub-federated video streaming platform. P
CVE-2026-73210 (A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo ...)
NOT-FOR-US: Lookyloo PlaywrightCapture
CVE-2026-73162 (Affected versions of MISP cti-transmute expose several state-changing ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: cti-transmute
CVE-2026-73161 (Affected versions of cti-transmute improperly handle conversion-table ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: cti-transmute
CVE-2026-73160 (Affected versions of cti-transmute contain an SSRF vulnerability in th ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: cti-transmute
CVE-2026-73159 (Affected versions of cti-transmute allow a tag's icon value to be stor ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: cti-transmute
CVE-2026-73158 (Affected versions of cti-transmute insufficiently validate saved graph ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: cti-transmute
CVE-2026-73157 (Affected versions of cti-transmute render data obtained from a remote ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: cti-transmute
CVE-2026-73156 (Affected versions of cti-transmute fail to HTML-escape attacker-contro ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: cti-transmute
CVE-2026-73155 (Affected versions of cti-transmute allow authenticated users to add or ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: cti-transmute
CVE-2026-73140 (Affected versions of cti-transmute fail to apply comment-level access- ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: cti-transmute
CVE-2026-73090 (PeerTube is an ActivityPub-federated video streaming platform. Prior t ...)
- peertube <itp> (bug #950821)
CVE-2026-73089 (Browserslist is a configuration tool for sharing target browsers and N ...)
@@ -14874,9 +14874,9 @@ CVE-2026-72862 (Dokploy is a free, self-hostable Platform as a Service (PaaS). P
CVE-2026-72761 (The webhook URL validator in `website/notifications/webhooks.py` uses ...)
NOT-FOR-US: vulnerability-lookup
CVE-2026-72760 (Affected versions of MISP cti-transmute disclose users' email addresse ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: cti-transmute
CVE-2026-72759 (In affected versions of MISP cti-transmute, the conversion-history det ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: cti-transmute
CVE-2026-72751 (CTI-Transmute is affected by a stored cross-site scripting (XSS) vulne ...)
NOT-FOR-US: CTI-Transmute
CVE-2026-72740 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
@@ -26275,7 +26275,7 @@ CVE-2026-67181 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling v
- rust-rouille <unfixed> (bug #1142994)
NOTE: https://github.com/theopaid/CVE-2026-67181-HTTP-Request-Smuggling-via-Transfer-Encoding-Desynchronization-rouille-
CVE-2026-67178 (MISP installation scripts generated an Apache HTTP virtual-host config ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: MISP installation scripts
CVE-2026-67174 (Pivotick contains a DOM-based cross-site scripting vulnerability in it ...)
NOT-FOR-US: Pivotick
CVE-2026-67173 (Pivotick did not validate the URL scheme of node imagePath values deri ...)
@@ -42811,7 +42811,7 @@ CVE-2026-6541 (Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <
CVE-2026-62147 (The Tempo Operator's gateway component failed to consistently apply na ...)
NOT-FOR-US: Red Hat Tempo Operator
CVE-2026-62143 (A Server-Side Request Forgery (SSRF) protection bypass existed in the ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: MISP addon
CVE-2026-61985 (Missing Authorization vulnerability in magepeopleteam Car Rental Manag ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-61983 (Missing Authorization vulnerability in andy_moyle Church Admin church- ...)
@@ -44703,7 +44703,7 @@ CVE-2026-7558 (The Age Verification & Identity Verification by Token of Trust pl
CVE-2026-6910 (The Bookero.pl \u2013 system rezerwacji online plugin for WordPress is ...)
NOT-FOR-US: WordPress plugin
CVE-2026-61474 (An improper authorization check in MISP\u2019s attribute creation endp ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-61344 (The Superior Court of California Hearing Reminder Service at https://w ...)
NOT-FOR-US: Superior Court of California Hearing Reminder Service
CVE-2026-61343 (LibreBooking's email template editor save action passes the submitted ...)
@@ -45586,9 +45586,9 @@ CVE-2026-6280 (Exposure of sensitive information due to incompatible policies vu
CVE-2026-6230 (The Tainacan plugin for WordPress is vulnerable to time-based blind SQ ...)
NOT-FOR-US: WordPress plugin
CVE-2026-60125 (MISP\u2019s importModule() path used getEnabledModule() to resolve a s ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-60124 (An authorization bypass in MISP\u2019s EventsController::importModule( ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-60102 (Horde Virtual File System (VFS) API before 3.0.1 contains an OS comman ...)
- php-horde-vfs <unfixed> (bug #1143051)
[bookworm] - php-horde-vfs <end-of-life> (EOL in bookworm LTS)
@@ -59232,17 +59232,17 @@ CVE-2026-56450 (AIL did not restrict repeated failed attempts to verify a two-fa
CVE-2026-56448 (A path traversal vulnerability exists in AIL Framework before the rele ...)
NOT-FOR-US: AIL framework
CVE-2026-56447 (MISP allowed an authenticated site administrator to set the Kafka_rdka ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-56446 (MISP allowed a site administrator to configure an arbitrary filesystem ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-56425 (The Azure Active Directory (AAD) authentication implementation contain ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-56424 (MISP core contained multiple broken access-control flaws where authori ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-56423 (MISP Core contained broken access-control checks in the bulk deletion ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-56422 (Multiple MISP core controllers and model capture paths accepted client ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-56109 (The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 c ...)
- alsa-lib 1.2.16.1-1 (unimportant)
NOTE: https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/
@@ -64228,29 +64228,29 @@ CVE-2026-9061 (The Store Locator WordPress plugin before 1.6.9 does not sanitize
CVE-2026-6676 (Heap buffer out-of-bounds write vulnerability in Avira Antivirus engin ...)
NOT-FOR-US: Avira
CVE-2026-54398 (An authorization flaw in MISP\u2019s object add/edit handling allowed ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54397 (A vulnerability in MISP\u2019s non-REST event editing path allowed an ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54396 (An information disclosure vulnerability exists in the MISP AuthKey edi ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54395 (MISP contains a reflected cross-site scripting vulnerability in the Ui ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54394 (MISP contains a path traversal vulnerability in OrganisationsControlle ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54393 (A stored cross-site scripting vulnerability exists in MISP when the Ov ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54362 (An incorrect visibility condition in the MISP event template builder a ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54361 (MISP contained multiple mass assignment vulnerabilities in the handlin ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54360 (A mass assignment vulnerability exists in MISP\u2019s sharing group cr ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54359 (MISP contains an insecure default configuration in which the Security. ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54358 (An incorrect authorization vulnerability in MISP allows an organizatio ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54357 (An improper authorization vulnerability in MISP allowed an authenticat ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-54231 (A content injection vulnerability was found in the ABRT post-create ev ...)
NOT-FOR-US: abrt/libreport
CVE-2026-54230 (A symlink following vulnerability was found in the ABRT post-create ev ...)
@@ -65660,7 +65660,7 @@ CVE-2026-53698 (Silverpeas through 6.4.6 mishandles the "Personal space" feature
CVE-2026-53694 (Improper Neutralization of Argument Delimiters in a Command ('Argument ...)
NOT-FOR-US: Nomachine
CVE-2026-53693 (A stored cross-site scripting vulnerability existed in MISPBSimVis tag ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: BSimVis
CVE-2026-53689 (libnfs through 6.0.2 before 55c18ea does not validate a string size, l ...)
{DLA-4689-1}
- libnfs 5.0.2-1.1 (bug #1139731)
@@ -71389,21 +71389,21 @@ CVE-2026-22054 (Active IQ Config Advisor version 6.7.3 contains hard-coded crede
CVE-2026-10880 (OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the l ...)
NOT-FOR-US: OSNexus QuantaStor SDS Manager
CVE-2026-10868 (A mass assignment vulnerability exists in the MISP user edit functiona ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-10864 (A vulnerability in the MISP dashboard widgets allowed an authenticated ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-10863 (A security issue was fixed in the correlations over-correlation endpoi ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-10861 (An open redirect vulnerability existed in MISP UsersController::routea ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-10860 (A logic error in the MISP CRUD component delete handler allowed valida ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-10856 (A URL validation flaw in the MISP dashboard button widget allowed a cr ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-10855 (An authorization flaw existed in the MISP Event Template Importer over ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-10854 (A visibility control issue in the event template creation workflow all ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-10843 (A flaw was found in the OpenShift Cloud Credential Operator Mint-mode ...)
NOT-FOR-US: Red Hat OpenShift
CVE-2026-10840 (A flaw was found in the OpenShift Pipelines operator. The tekton-sched ...)
@@ -72603,7 +72603,7 @@ CVE-2026-10622 (Improper Authentication in REST API in Collibra Agent, allows a
CVE-2026-10621 (Path traversal in restore handler in Collibra Agent, allows an attacke ...)
NOT-FOR-US: Collibra Agent
CVE-2026-10611 (An authentication bypass vulnerability exists in MISP when LDAP mixed ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-10606 (A vulnerability was determined in DedeCMS 5.7.88. The affected element ...)
NOT-FOR-US: DedeCMS
CVE-2026-10591 (Insufficient access control restrictions in the file write tool in Ama ...)
@@ -81644,9 +81644,9 @@ CVE-2026-9141 (Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an
CVE-2026-9139 (Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-c ...)
NOT-FOR-US: Taiko AG1000-01A SMS Alert Gateway
CVE-2026-9137 (The CSP report endpoint in MISP intended to limit logged CSP reports t ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-9136 (A vulnerability was identified in the ShadowAttribute proposal creatio ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-9133 (Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws ...)
NOT-FOR-US: Amazon
CVE-2026-9129 (A path traversal vulnerability exists in the Altium Enterprise Server ...)
@@ -81950,7 +81950,7 @@ CVE-2026-9100 (The MongoDB C Driver's legacy GridFS API accepts malformed file m
CVE-2026-9087 (A flaw was found in Keycloak. The cross-session verification proof is ...)
- keycloak <itp> (bug #1088287)
CVE-2026-9084 (MISP\u2019s OIDC authentication plugin allowed automatic linking of an ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-9065 (SureCart version prior to 4.2.1 are vulnerable to authenticated SQL in ...)
NOT-FOR-US: SureCart
CVE-2026-9064 (A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...)
@@ -85251,11 +85251,11 @@ CVE-2026-44423 (ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api
CVE-2026-44418 (EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlie ...)
NOT-FOR-US: EcclesiaCRM
CVE-2026-44381 (MISP is an open source threat intelligence and sharing platform. Prior ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-44380 (MISP is an open source threat intelligence and sharing platform. Prior ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-44379 (MISP is an open source threat intelligence and sharing platform. Prior ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-44377 (CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authent ...)
NOT-FOR-US: CubeCart
CVE-2026-44376 (CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthe ...)
@@ -85269,9 +85269,9 @@ CVE-2026-44369 (CVAT is an open source interactive video and image annotation to
CVE-2026-44368 (PyQuorum is a cryptographic library for secret sharing and key managem ...)
NOT-FOR-US: PyQuorum
CVE-2026-44364 (MISP modules are autonomous modules that can be used to extend MISP fo ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: MISP modules
CVE-2026-44363 (MISP modules are autonomous modules that can be used to extend MISP fo ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: MISP modules
CVE-2026-44351 (fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6 ...)
NOT-FOR-US: fast-jwt
CVE-2026-44295 (protobufjs-cli is the command line add-on for protobuf.js. Prior to 1. ...)
@@ -90635,7 +90635,7 @@ CVE-2026-8083 (A vulnerability was found in SourceCodester Pharmacy Sales and In
CVE-2026-8081 (A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Af ...)
NOT-FOR-US: CLIProxyAPI
CVE-2026-8080 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-7821 (Improper certificate validation in Ivanti EPMM beforeversions 12.6.1.1 ...)
NOT-FOR-US: Ivanti
CVE-2026-7415 (The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to all ...)
@@ -106869,7 +106869,7 @@ CVE-2026-39974 (n8n-MCP is a Model Context Protocol (MCP) server that provides A
CVE-2026-39972 (Mercure is a protocol for pushing data updates to web browsers and oth ...)
NOT-FOR-US: Mercure
CVE-2026-39962 (MISP is an open source threat intelligence and sharing platform. Prior ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2026-39961 (Aiven Operator allows you to provision and manage Aiven Services from ...)
NOT-FOR-US: Aiven Operator
CVE-2026-39959 (Tmds.DBus provides .NET libraries for working with D-Bus from .NET. Tm ...)
@@ -161498,7 +161498,7 @@ CVE-2023-36337 (A reflected cross-site scripting (XSS) vulnerability in the comp
CVE-2025-67907
REJECTED
CVE-2025-67906 (In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp a ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2025-67901 (openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other p ...)
NOT-FOR-US: openrsync
CVE-2025-67900 (NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF ...)
@@ -168562,11 +168562,11 @@ CVE-2025-12143 (Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbo
CVE-2025-11156 (Netskope was notified about a potential gap in its agent (NS Client) o ...)
NOT-FOR-US: Netskope
CVE-2025-66386 (app/Model/EventReport.php in MISP before 2.5.27 allows path traversal ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2025-66385 (UsersController::edit in Cerebrate before 1.30 allows an authenticated ...)
NOT-FOR-US: Cerebrate
CVE-2025-66384 (app/Controller/EventsController.php in MISP before 2.5.24 has invalid ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2025-66382 (In libexpat through 2.7.3, a crafted file with an approximate size of ...)
- expat <unfixed> (bug #1121543)
[trixie] - expat <postponed> (Minor issue, revisit when fixed upstream)
@@ -248917,11 +248917,11 @@ CVE-2024-7577 (IBM InfoSphere Information Server 11.7 could disclose sensitive u
CVE-2024-6875 (A vulnerability was found in the Infinispan component in Red Hat Data ...)
NOT-FOR-US: Infinispan component in Red Hat Data Grid
CVE-2024-58130 (In app/Controller/Component/RestResponseComponent.php in MISP before 2 ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-58129 (In MISP before 2.4.193, menu_custom_right_link_html parameters can be ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-58128 (In MISP before 2.4.193, menu_custom_right_link parameters can be set v ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-57083 (A prototype pollution in the component Module.mergeObjects (redoc/bund ...)
NOT-FOR-US: redoc
CVE-2024-56975 (InvoicePlane (all versions tested as of December 2024) v.1.6.11 and be ...)
@@ -264357,7 +264357,7 @@ CVE-2024-9601 (The Qubely \u2013 Advanced Gutenberg Blocks plugin for WordPress
CVE-2024-7052 (The Forminator Forms WordPress plugin before 1.38.3 does not sanitise ...)
NOT-FOR-US: WordPress plugin
CVE-2024-57969 (app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-57782 (An issue in Docker-proxy v18.09.0 allows attackers to cause a denial o ...)
NOTE: Bogus report for possinly the use of a proxy in a very old Docker release
CVE-2024-57378 (Wazuh SIEM version 4.8.2 is affected by a broken access control vulner ...)
@@ -285251,9 +285251,9 @@ CVE-2023-50913 (Oxide control plane software before 5 allows SSRF.)
CVE-2023-48010 (STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism ...)
NOT-FOR-US: STMicroelectronics SPC58
CVE-2024-54675 (app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2. ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-54674 (app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-54221 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
NOT-FOR-US: WordPress plugin
CVE-2024-54014 (Improper authorization in handler for custom URL scheme issue in 'Skyl ...)
@@ -307820,7 +307820,7 @@ CVE-2024-1578 (The MiCard PLUS Ci and MiCard PLUS BLE reader products developed
CVE-2024-8869 (A vulnerability classified as critical has been found in TOTOLINK A720 ...)
NOT-FOR-US: TOTOLINK
CVE-2024-46918 (app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-44059 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
NOT-FOR-US: WordPress plugin
CVE-2024-44058 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
@@ -310909,7 +310909,7 @@ CVE-2024-45527 (REDCap 14.7.0 allows HTML injection via the project title of a N
CVE-2024-45522 (Linen before cd37c3e does not verify that the domain is linen.dev or w ...)
NOT-FOR-US: Linen
CVE-2024-45509 (In MISP through 2.4.196, app/Controller/BookmarksController.php does n ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-45508 (HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ...)
- htmldoc 1.9.18-2 (bug #1081236)
[bookworm] - htmldoc <no-dsa> (Minor issue)
@@ -360747,9 +360747,9 @@ CVE-2024-29864 (Distrobox before 1.7.0.1 allows attackers to execute arbitrary c
CVE-2024-29862 (The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4. ...)
NOT-FOR-US: Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder
CVE-2024-29859 (In MISP before 2.4.187, add_misp_export in app/Controller/EventsContro ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-29858 (In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsCo ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-29474 (OneBlog v2.3.4 was discovered to contain a stored cross-site scripting ...)
NOT-FOR-US: OneBlog
CVE-2024-29473 (OneBlog v2.3.4 was discovered to contain a stored cross-site scripting ...)
@@ -371475,9 +371475,9 @@ CVE-2024-25678 (In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation
CVE-2024-25677 (In Min before 1.31.0, local files are not correctly treated as unique ...)
NOT-FOR-US: Min
CVE-2024-25675 (An issue was discovered in MISP before 2.4.184. A client does not need ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-25674 (An issue was discovered in MISP before 2.4.184. Organisation logo uplo ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2024-25454 (Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference ...)
NOT-FOR-US: Bento4
CVE-2024-25453 (Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference ...)
@@ -382036,7 +382036,7 @@ CVE-2023-6553 (The Backup Migration plugin for WordPress is vulnerable to Remote
CVE-2023-5310 (A denial of service vulnerability exists in all Silicon Labs Z-Wave co ...)
NOT-FOR-US: Silicon Labs Z-Wavecontroller and endpoint devices running Z-Wave SDK
CVE-2023-50918 (app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandl ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-50917 (MajorDoMo (aka Major Domestic Module) before 0662e5e allows command ex ...)
NOT-FOR-US: MajorDoMo (aka Major Domestic Module)
CVE-2023-50871 (In JetBrains YouTrack before 2023.3.22268 authorization check for inli ...)
@@ -385297,7 +385297,7 @@ CVE-2023-6474 (A vulnerability has been found in PHPGurukul Nipah Virus Testing
CVE-2023-6473 (A vulnerability, which was classified as problematic, was found in Sou ...)
NOT-FOR-US: SourceCodester Online Quiz System
CVE-2023-49926 (app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-47100
REJECTED
CVE-2023-6472 (A vulnerability, which was classified as problematic, has been found i ...)
@@ -387322,15 +387322,15 @@ CVE-2023-6020 (LFI in Ray's /static/ directory allows attackers to read any file
CVE-2023-6014 (An attacker is able to arbitrarily create an account in MLflow bypassi ...)
NOT-FOR-US: mlflow
CVE-2023-48659 (An issue was discovered in MISP before 2.4.176. app/Controller/AppCont ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-48658 (An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-48657 (An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-48656 (An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-48655 (An issue was discovered in MISP before 2.4.176. app/Controller/Compone ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-48649 (Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on t ...)
NOT-FOR-US: Concrete CMS
CVE-2023-48648 (Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized ac ...)
@@ -401837,7 +401837,7 @@ CVE-2023-41104 (libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x
CVE-2023-41100 (An issue was discovered in the hcaptcha (aka hCaptcha for EXT:form) ex ...)
NOT-FOR-US: TYPO3 extension
CVE-2023-41098 (An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsC ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-40370 (IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vuln ...)
NOT-FOR-US: IBM
CVE-2023-40282 (Improper authentication vulnerability in Rakuten WiFi Pocket all versi ...)
@@ -403083,7 +403083,7 @@ CVE-2023-40253 (Improper Authentication vulnerability in Genians Genian NAC V4.0
CVE-2023-40235 (An NTLM Hash Disclosure was discovered in ArchiMate Archi before 5.1.0 ...)
NOT-FOR-US: ArchiMate Archi
CVE-2023-40224 (MISP 2.4.174 allows XSS in app/View/Events/index.ctp.)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-40014 (OpenZeppelin Contracts is a library for secure smart contract developm ...)
NOT-FOR-US: OpenZeppelin Contracts
CVE-2023-3824 (In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* bef ...)
@@ -409003,9 +409003,9 @@ CVE-2023-37360 (pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript
NOTE: https://github.com/manugarg/pacparser/security/advisories/GHSA-62q6-v997-f7v9
NOTE: https://github.com/manugarg/pacparser/commit/0bf0636de624996fe202b51eec8a58abd774269e (v1.4.2)
CVE-2023-37307 (In MISP before 2.4.172, title_for_layout is not properly sanitized in ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-37306 (MISP 2.4.172 mishandles different certificate file extensions in serve ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-37305 (An issue was discovered in the ProofreadPage (aka Proofread Page) exte ...)
NOT-FOR-US: MediaWiki extension ProofreadPage
CVE-2023-37304 (An issue was discovered in the DoubleWiki extension for MediaWiki thro ...)
@@ -422369,7 +422369,7 @@ CVE-2023-28886
CVE-2023-28885 (The MyLink infotainment system (build 2021.3.26) in General Motors Che ...)
NOT-FOR-US: MyLink infotainment system
CVE-2023-28884 (In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-28883 (In Cerebrate 1.13, a blind SQL injection exists in the searchAll API e ...)
NOT-FOR-US: Cerebrate
CVE-2023-28882 (Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial ...)
@@ -423487,9 +423487,9 @@ CVE-2015-10096 (A vulnerability, which was classified as critical, was found in
CVE-2023-28608
RESERVED
CVE-2023-28607 (js/event-graph.js in MISP before 2.4.169 allows XSS via the event-grap ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-28606 (js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph no ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-28605
RESERVED
CVE-2023-28604 (The fluid_components (aka Fluid Components) extension before 3.5.0 for ...)
@@ -431059,9 +431059,9 @@ CVE-2023-26057 (An XXE issue was discovered in Nokia NetAct before 22 FP2211 via
CVE-2023-0920
RESERVED
CVE-2022-48329 (MISP before 2.4.166 unsafely allows users to use the order parameter, ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-48328 (app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.1 ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-4325 (A vulnerability, which was classified as problematic, has been found i ...)
NOT-FOR-US: NHN TOAST UI Chart
CVE-2017-20179 (A vulnerability was found in InSTEDD Pollit 2.3.1. It has been rated a ...)
@@ -437287,7 +437287,7 @@ CVE-2023-24072
CVE-2023-24071
RESERVED
CVE-2023-24070 (app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an X ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-24069 (Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an att ...)
- signal-desktop <itp> (bug #842943)
CVE-2023-24068 (Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an att ...)
@@ -437438,11 +437438,11 @@ CVE-2023-24030 (An open redirect vulnerability exists in the /preauth Servlet in
CVE-2023-24029 (In Progress WS_FTP Server before 8.8, it is possible for a host admini ...)
NOT-FOR-US: Progress WS_FTP Server
CVE-2023-24028 (In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorre ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-24027 (In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a netwo ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-24026 (In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerabilit ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2023-24025 (CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2 ...)
NOT-FOR-US: CRYSTALS-DILITHIUM
CVE-2023-24024
@@ -444167,7 +444167,7 @@ CVE-2022-47929 (In the Linux kernel before 6.1.6, a NULL pointer dereference bug
- linux 6.1.7-1
NOTE: https://git.kernel.org/linus/96398560f26aa07e8f2969d73c8197e6a6d10407 (6.2-rc4)
CVE-2022-47928 (In MISP before 2.4.167, there is XSS in the template file uploads in a ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-47927 (An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.3 ...)
{DLA-3489-1}
- mediawiki 1:1.39.1-1
@@ -463952,7 +463952,7 @@ CVE-2022-42726
CVE-2022-42725 (Warpinator through 1.2.14 allows access outside of an intended directo ...)
NOT-FOR-US: Warpinator
CVE-2022-42724 (app/Controller/UsersController.php in MISP before 2.4.164 allows attac ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-42723
RESERVED
CVE-2022-42722 (In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers ...)
@@ -500789,19 +500789,19 @@ CVE-2022-29536 (In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML docu
CVE-2022-29535 (Zoho ManageEngine OPManager through 125588 allows SQL Injection via a ...)
NOT-FOR-US: Zoho ManageEngine
CVE-2022-29534 (An issue was discovered in MISP before 2.4.158. In UsersController.php ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-29533 (An issue was discovered in MISP before 2.4.158. There is XSS in app/Co ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-29532 (An issue was discovered in MISP before 2.4.158. There is XSS in the ce ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-29531 (An issue was discovered in MISP before 2.4.158. There is stored XSS in ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-29530 (An issue was discovered in MISP before 2.4.158. There is stored XSS in ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-29529 (An issue was discovered in MISP before 2.4.158. There is stored XSS vi ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-29528 (An issue was discovered in MISP before 2.4.158. PHAR deserialization c ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-1419 (The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_ ...)
{DSA-5173-1}
- linux 5.5.13-1
@@ -507543,13 +507543,13 @@ CVE-2022-27248 (A directory traversal vulnerability in IdeaRE RefTree before 202
CVE-2022-27247 (onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an att ...)
NOT-FOR-US: cdSoft Winhotel.MX
CVE-2022-27246 (An issue was discovered in MISP before 2.4.156. An SVG org logo (which ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-27245 (An issue was discovered in MISP before 2.4.156. app/Model/Server.php d ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-27244 (An issue was discovered in MISP before 2.4.156. A malicious site admin ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-27243 (An issue was discovered in MISP before 2.4.156. app/View/Users/terms.c ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2022-27242 (A vulnerability has been identified in OpenV2G (V0.9.4). The OpenV2G E ...)
NOT-FOR-US: OpenV2G / Siemens
CVE-2022-27241 (A vulnerability has been identified in Mendix Applications using Mendi ...)
@@ -542217,7 +542217,7 @@ CVE-2021-41328
CVE-2021-41327
RESERVED
CVE-2021-41326 (In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles p ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-41325 (Broken access control for user creation in Pydio Cells 2.2.9 allows re ...)
NOT-FOR-US: Pydio Cells
CVE-2021-41324 (Directory traversal in the Copy, Move, and Delete features in Pydio Ce ...)
@@ -547400,7 +547400,7 @@ CVE-2020-36474 (SafeCurl before 0.9.2 has a DNS rebinding vulnerability.)
CVE-2021-39303 (The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka P ...)
NOT-FOR-US: Jamf Pro
CVE-2021-39302 (MISP 2.4.148, in certain configurations, allows SQL injection via the ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-39301 (Potential vulnerabilities have been identified in UEFI firmware (BIOS) ...)
NOT-FOR-US: HP
CVE-2021-39300 (Potential vulnerabilities have been identified in UEFI firmware (BIOS) ...)
@@ -551591,9 +551591,9 @@ CVE-2021-37745
CVE-2021-37744
RESERVED
CVE-2021-37743 (app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored X ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-37742 (app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.14 ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-37741 (ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vul ...)
NOT-FOR-US: ManageEngine
CVE-2021-37740 (A denial of service vulnerability exists in MDT's firmware for the KNX ...)
@@ -552141,7 +552141,7 @@ CVE-2021-37536
CVE-2021-37535 (SAP NetWeaver Application Server Java (JMS Connector Service) - versio ...)
NOT-FOR-US: SAP
CVE-2021-37534 (app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-37533 (Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host fr ...)
{DSA-5307-1 DLA-3251-1}
- libcommons-net-java 3.9.0-1 (bug #1025910)
@@ -555266,7 +555266,7 @@ CVE-2021-36213 (HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 defa
NOTE: https://discuss.hashicorp.com/t/hcsec-2021-16-consul-s-application-aware-intentions-deny-action-fails-open-when-combined-with-default-deny-policy/26855
NOTE: https://github.com/hashicorp/consul/pull/10619
CVE-2021-36212 (app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored X ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-3637 (A flaw was found in keycloak-model-infinispan in keycloak versions bef ...)
- keycloak <itp> (bug #1088287)
CVE-2021-36211
@@ -557070,7 +557070,7 @@ CVE-2021-35504 (Afian FileRun 2021.03.26 allows Remote Code Execution (by admini
CVE-2021-35503 (Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For ...)
NOT-FOR-US: Afian FileRun
CVE-2021-35502 (app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-3622 (A flaw was found in the hivex library. This flaw allows an attacker to ...)
- hivex 1.3.21-1 (bug #991860)
[bullseye] - hivex <no-dsa> (Minor issue)
@@ -566787,7 +566787,7 @@ CVE-2021-31782
CVE-2021-31781
RESERVED
CVE-2021-31780 (In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing grou ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-31779 (The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows ...)
NOT-FOR-US: Typo3 extension
CVE-2021-31778 (The media2click (aka 2 Clicks for External Media) extension 1.x before ...)
@@ -576993,7 +576993,7 @@ CVE-2021-27905 (The ReplicationHandler (normally registered at "/replication" un
NOTE: https://lists.apache.org/thread.html/r0ddc3a82bd7523b1453cb7a5e09eb5559517145425074a42eb326b10%40%3Cannounce.apache.org%3E
NOTE: Server components disabled in 3.6.2+dfsg-23, using that as the fixed version
CVE-2021-27904 (An issue was discovered in app/Model/SharingGroupServer.php in MISP 2. ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-27903 (An issue was discovered in Craft CMS before 3.6.7. In some circumstanc ...)
NOT-FOR-US: Craft CMS
CVE-2021-27902 (An issue was discovered in Craft CMS before 3.6.0. In some circumstanc ...)
@@ -583402,7 +583402,7 @@ CVE-2020-36195 (An SQL injection vulnerability has been reported to affect QNAP
CVE-2020-36194 (An XSS vulnerability has been reported to affect QNAP NAS running QTS ...)
NOT-FOR-US: QNAP
CVE-2021-3184 (MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-3183 (Files.com Fat Client 3.3.6 allows authentication bypass because the cl ...)
NOT-FOR-US: Files.com Fat Client
CVE-2021-3182 (D-Link DCS-5220 devices have a buffer overflow. NOTE: This vulnerabili ...)
@@ -583432,11 +583432,11 @@ CVE-2021-25327 (Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-sit
CVE-2021-25326 (Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrec ...)
NOT-FOR-US: Skyworth Digital Technology RN510
CVE-2021-25325 (MISP 2.4.136 has XSS via galaxy cluster element values to app/View/Gal ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-25324 (MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster n ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-25323 (The default setting of MISP 2.4.136 did not enable the requirements (a ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2021-25322 (A UNIX Symbolic Link (Symlink) Following vulnerability in python-Hyper ...)
- hyperkitty <not-affected> (SuSE-specific packaging issue)
CVE-2021-25321 (A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of ...)
@@ -600990,7 +600990,7 @@ CVE-2020-29573 (sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6
NOTE: Fixed by: https://sourceware.org/git/?p=glibc.git;h=d81f90ccd0109de9ed78aeeb8d86e2c6d4600690 (glibc-2.22)
NOTE: Fixed by: https://sourceware.org/git/?p=glibc.git;h=8df4e219e43a4a257d0759b54fef8c488e2f282e (glibc-2.23)
CVE-2020-29572 (app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-29571 (An issue was discovered in Xen through 4.14.x. A bounds check common t ...)
{DSA-4812-1}
- xen 4.14.0+88-g1d1d1f5391-1
@@ -602528,7 +602528,7 @@ CVE-2020-29007 (The Score extension through 0.3.0 for MediaWiki has a remote cod
NOTE: https://phabricator.wikimedia.org/T257062
NOTE: https://www.mediawiki.org/wiki/Extension:Score/2021_security_advisory
CVE-2020-29006 (MISP before 2.4.135 lacks an ACL check, related to app/Controller/Gala ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-29005 (The API in the Push extension for MediaWiki through 1.35 used cleartex ...)
NOT-FOR-US: Push extension for MediaWiki
CVE-2020-29004 (The API in the Push extension for MediaWiki through 1.35 did not requi ...)
@@ -602715,7 +602715,7 @@ CVE-2020-28948 (Archive_Tar through 1.4.10 allows an unserialization attack beca
NOTE: https://github.com/pear/Archive_Tar/commit/0670a05fdab997036a3fc3ef113b8f5922e574da
NOTE: https://www.drupal.org/sa-core-2020-013
CVE-2020-28947 (In MISP 2.4.134, XSS exists in the template element index view because ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-28946 (An improper webserver configuration on Plum IK-401 devices with firmwa ...)
NOT-FOR-US: Plum IK-401 devices
CVE-2020-28945 (OX App Suite 7.10.4 and earlier allows XSS via crafted content to reac ...)
@@ -607711,7 +607711,7 @@ CVE-2020-28045 (An unsigned-library issue was discovered in ProlinOS through 2.4
CVE-2020-28044 (An attacker with physical access to a PAX Point Of Sale device with Pr ...)
NOT-FOR-US: ProlinOS
CVE-2020-28043 (MISP through 2.4.133 allows SSRF in the REST client via the use_full_p ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-28042 (ServiceStack before 5.9.2 mishandles JWT signature verification unless ...)
NOT-FOR-US: ServiceStack
CVE-2020-28041 (The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 ...)
@@ -614018,7 +614018,7 @@ CVE-2020-25768 (Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10
CVE-2020-25767 (An issue was discovered in HCC Embedded NicheStack IPv4 4.1. The dnc_c ...)
NOT-FOR-US: HCC Embedded NicheStack
CVE-2020-25766 (An issue was discovered in MISP before 2.4.132. It can perform an unwa ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-25765 (Addressed remote code execution vulnerability in reg_device.php due to ...)
NOT-FOR-US: Western Digital My Cloud Devices
CVE-2020-25764
@@ -618258,7 +618258,7 @@ CVE-2020-24087
CVE-2020-24086
RESERVED
CVE-2020-24085 (A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-24084
RESERVED
CVE-2020-24083
@@ -636555,7 +636555,7 @@ CVE-2020-15713 (rConfig 3.9.5 is vulnerable to SQL injection. A remote authentic
CVE-2020-15712 (rConfig 3.9.5 could allow a remote authenticated attacker to traverse ...)
NOT-FOR-US: rConfig
CVE-2020-15711 (In MISP before 2.4.129, setting a favourite homepage was not CSRF prot ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-15710 (Potential double free in Bluez 5 module of PulseAudio could allow a lo ...)
- pulseaudio <not-affected> (Issue in Ubuntu-specific patch)
NOTE: https://bugs.launchpad.net/ubuntu/%2Bsource/pulseaudio/%2Bbug/1884738
@@ -637433,9 +637433,9 @@ CVE-2020-15414
CVE-2020-15413
RESERVED
CVE-2020-15412 (An issue was discovered in MISP 2.4.128. app/Controller/EventsControll ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-15411 (An issue was discovered in MISP 2.4.128. app/Controller/AttributesCont ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-15410
RESERVED
CVE-2020-15409
@@ -638552,7 +638552,7 @@ CVE-2020-14971 (Pi-hole through 5.0 allows code injection in piholedhcp (the Sta
CVE-2020-14970
RESERVED
CVE-2020-14969 (app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribu ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-14968 (An issue was discovered in the jsrsasign package before 8.0.17 for Nod ...)
NOT-FOR-US: jsrsasign
CVE-2020-14967 (An issue was discovered in the jsrsasign package before 8.0.18 for Nod ...)
@@ -643737,7 +643737,7 @@ CVE-2020-13155 (clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML
CVE-2020-13154 (Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-priv ...)
NOT-FOR-US: Zoho
CVE-2020-13153 (app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-13152 (A remote user can create a specially crafted M3U file, media playlist ...)
- amarok <removed> (unimportant)
NOTE: Elevated resource usage in client application, no security impact
@@ -644314,7 +644314,7 @@ CVE-2020-12891 (AMD Radeon Software may be vulnerable to DLL Hijacking through p
CVE-2020-12890 (Improper handling of pointers in the System Management Mode (SMM) hand ...)
NOT-FOR-US: AMD
CVE-2020-12889 (MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across us ...)
- NOT-FOR-US: MISP
+ NOT-FOR-US: MISP-maltego
CVE-2020-12888 (The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles atte ...)
{DLA-2420-1 DLA-2385-1}
- linux 5.8.7-1
@@ -649441,7 +649441,7 @@ CVE-2020-11460
CVE-2020-11459
RESERVED
CVE-2020-11458 (app/Model/feed.php in MISP before 2.4.124 allows administrators to cho ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-11457 (pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php ...)
NOT-FOR-US: pfSense
CVE-2020-11456 (LimeSurvey before 4.1.12+200324 has stored XSS in application/views/ad ...)
@@ -652916,9 +652916,9 @@ CVE-2020-10249 (BWA DiREX-Pro 1.2181 devices allow full path disclosure via an i
CVE-2020-10248 (BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwo ...)
NOT-FOR-US: BWA DiREX-Pro devices
CVE-2020-10247 (MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-10246 (MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-10245 (CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control run ...)
NOT-FOR-US: CODESYS
CVE-2020-10244 (JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.)
@@ -656188,15 +656188,15 @@ CVE-2020-8896 (A Buffer Overflow vulnerability in the khcrypt implementation in
CVE-2020-8895 (Untrusted Search Path vulnerability in the windows installer of Google ...)
NOT-FOR-US: windows installer of Google Earth Pro
CVE-2020-8894 (An issue was discovered in MISP before 2.4.121. ACLs for discussion th ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-8893 (An issue was discovered in MISP before 2.4.121. The Galaxy view contai ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-8892 (An issue was discovered in MISP before 2.4.121. It did not consider th ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-8891 (An issue was discovered in MISP before 2.4.121. It did not canonicaliz ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-8890 (An issue was discovered in MISP before 2.4.121. It mishandled time ske ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2020-8889 (The ShipStation.com plugin 1.0 for CS-Cart allows remote attackers to ...)
NOT-FOR-US: CS-Cart plugin
CVE-2020-8888
@@ -675800,7 +675800,7 @@ CVE-2019-19381 (oauth/oauth2/v1/saml/ in Abacus OAuth Login 2019_01_r4_20191021_
CVE-2019-19380
RESERVED
CVE-2019-19379 (In app/Controller/TagsController.php in MISP 2.4.118, users can bypass ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2019-19378 (In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image ...)
- linux <unfixed> (unimportant)
NOTE: raid 5/6 is marked as not production ready for btrfs
@@ -688220,7 +688220,7 @@ CVE-2019-16204 (Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and
CVE-2019-16203 (Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the ...)
NOT-FOR-US: Brocade Fabric OS
CVE-2019-16202 (MISP before 2.4.115 allows privilege escalation in certain situations. ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2019-16201 (WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5 ...)
{DSA-4587-1 DSA-4586-1 DLA-3408-1 DLA-2330-1 DLA-2027-1 DLA-2007-1}
- ruby2.5 2.5.7-1
@@ -694918,7 +694918,7 @@ CVE-2019-14287 (In Sudo before 1.8.28, an attacker with access to a Runas ALL su
NOTE: Fix test regression: https://www.sudo.ws/repos/sudo/rev/db06a8336c09
NOTE: Patch: https://www.openwall.com/lists/oss-security/2019/10/15/2 (1.8.5, 1.8.10)
CVE-2019-14286 (In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnera ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2019-14285
RESERVED
CVE-2015-9288 (The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allo ...)
@@ -699842,7 +699842,7 @@ CVE-2019-12870 (An issue was discovered in PHOENIX CONTACT PC Worx through 1.86,
CVE-2019-12869 (An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Wo ...)
NOT-FOR-US: PHOENIX CONTACT PC Worx
CVE-2019-12868 (app/Model/Server.php in MISP 2.4.109 allows remote command execution b ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2019-12867 (Certain actions could cause privilege escalation for issue attachments ...)
NOT-FOR-US: JetBrains YouTrack
CVE-2019-12866 (An Insecure Direct Object Reference, with Authorization Bypass through ...)
@@ -700065,7 +700065,7 @@ CVE-2009-5157 (On Linksys WAG54G2 1.00.10 devices, there is authenticated comman
CVE-2009-5156 (An issue was discovered on ASMAX AR-804gu 66.34.1 devices. There is Co ...)
NOT-FOR-US: ASMAX AR-804gu 66.34.1 devices
CVE-2019-12794 (An issue was discovered in MISP 2.4.108. Organization admins could res ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2019-XXXX [security issues fixed in 1.8.5]
- rdesktop 1.8.6-1 (bug #930387)
[stretch] - rdesktop 1.8.6-2~deb9u1
@@ -702605,11 +702605,11 @@ CVE-2019-11817
CVE-2019-11816 (Incorrect access control in the WebUI in OPNsense before version 19.1. ...)
NOT-FOR-US: OPNsense
CVE-2019-11814 (An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.1 ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2019-11813 (An issue was discovered in app/View/Elements/Events/View/value_field.c ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2019-11812 (A persistent XSS issue was discovered in app/View/Helper/CommandHelper ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2019-11815 (An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the L ...)
{DSA-4465-1 DLA-1824-1}
- linux 4.19.37-1 (bug #928989)
@@ -707031,7 +707031,7 @@ CVE-2019-10255 (An Open Redirect vulnerability for all browsers in Jupyter Noteb
NOTE: https://blog.jupyter.org/open-redirect-vulnerability-in-jupyter-jupyterhub-adf43583f1e4
NOTE: https://github.com/jupyter/notebook/commit/979e0bd15e794ceb00cc63737fcd5fd9addc4a99
CVE-2019-10254 (In MISP before 2.4.105, the app/View/Layouts/default.ctp default layou ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2019-10253 (A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ ...)
NOT-FOR-US: TeamMate+
CVE-2019-10252
@@ -710571,7 +710571,7 @@ CVE-2019-9484 (The Glen Dimplex Deutschland GmbH implementation of the Carel pCO
CVE-2019-9483 (Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows ...)
NOT-FOR-US: Amazon Ring Doorbell
CVE-2019-9482 (In MISP 2.4.102, an authenticated user can view sightings that they sh ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2019-9481
RESERVED
CVE-2019-9480
@@ -732285,7 +732285,7 @@ CVE-2018-19910
CVE-2018-19909
RESERVED
CVE-2018-19908 (An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Eve ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2018-1000859
REJECTED
CVE-2018-1000853
@@ -754428,7 +754428,7 @@ CVE-2018-12651 (A Reflected Cross Site Scripting (XSS) Vulnerability was discove
CVE-2018-12650 (Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting ...)
NOT-FOR-US: Adrenalin HRMS
CVE-2018-12649 (An issue was discovered in app/Controller/UsersController.php in MISP ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2018-12648 (The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Suppo ...)
[experimental] - exempi 2.5.0-1
- exempi 2.5.0-2 (low; bug #902175)
@@ -757829,7 +757829,7 @@ CVE-2018-11563 (An issue was discovered in Open Ticket Request System (OTRS) 6.0
NOTE: https://community.otrs.com/security-advisory-2018-02-security-update-for-otrs-framework/
NOTE: https://github.com/OTRS/otrs/commit/50861a2a1183a07daf99cc2e71395e79f022338f
CVE-2018-11562 (An issue was discovered in MISP 2.4.91. A vulnerability in app/View/El ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2018-11561 (An integer overflow in the unprotected distributeToken function of a s ...)
NOT-FOR-US: smart contract implementation for EETHER (EETHER)
CVE-2018-11560 (The webService binary on Insteon HD IP Camera White 2864-222 devices h ...)
@@ -758733,7 +758733,7 @@ CVE-2018-11247 (The JMX/RMI interface in Nasdaq BWise 5.0 does not require authe
CVE-2018-11246 (K7TSMngr.exe in K7Computing K7AntiVirus Premium 15.1.0.53 has a Memory ...)
NOT-FOR-US: K7Computing K7AntiVirus Premium
CVE-2018-11245 (app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2018-11244 (The BBE theme before 1.53 for WordPress allows a direct launch of an H ...)
NOT-FOR-US: WordPress theme
CVE-2018-11243 (PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attac ...)
@@ -764786,9 +764786,9 @@ CVE-2018-8951
CVE-2018-8950
RESERVED
CVE-2018-8949 (An issue was discovered in app/Model/Attribute.php in MISP before 2.4. ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2018-8948 (In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has mul ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2018-8947 (rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encodin ...)
NOT-FOR-US: rap2hpoutre Laravel Log Viewer
CVE-2018-1000141 (I, Librarian version 4.9 and earlier contains an Incorrect Access Cont ...)
@@ -770601,7 +770601,7 @@ CVE-2018-6927 (The futex_requeue function in kernel/futex.c in the Linux kernel
[stretch] - linux 4.9.80-1
NOTE: Fixed by: https://git.kernel.org/linus/fbe0e839d1e22d88810f3ee3e2f1479be4c0aa4a
CVE-2018-6926 (In app/Controller/ServersController.php in MISP 2.4.87, a server setti ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2018-6925 (In FreeBSD before 11.2-STABLE(r338986), 11.2-RELEASE-p4, 11.1-RELEASE- ...)
- kfreebsd-10 <removed> (unimportant)
NOTE: https://security.FreeBSD.org/advisories/FreeBSD-EN-18:11.listen.asc
@@ -791343,7 +791343,7 @@ CVE-2017-16948 (TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause
CVE-2017-16947
RESERVED
CVE-2017-16946 (The admin_edit function in app/Controller/UsersController.php in MISP ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2017-16945 (The standardrestorer binary in Arq 5.10 and earlier for Mac allows loc ...)
NOT-FOR-US: standardrestorer binary in Arq
CVE-2017-16942 (In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists ...)
@@ -792291,7 +792291,7 @@ CVE-2017-16803 (In Libav through 11.11 and 12.x through 12.1, the smacker_decode
NOTE: ffmpeg: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/cd4663dc80323ba64989d0c103d51ad3ee0e9c2f
NOTE: ffmpeg originally fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commitdiff/b829da363985cb2f80130bba304cc29a632f6446
CVE-2017-16802 (In the sharingGroupPopulateOrganisations function in app/webroot/js/mi ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2017-16804 (In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function ...)
{DSA-4191-1}
- redmine 3.4.2-1
@@ -796939,7 +796939,7 @@ CVE-2016-10514 (url_check_format in include/functions.inc.php in Piwigo before 2
CVE-2016-10513 (Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted ...)
- piwigo <removed>
CVE-2017-15216 (MISP before 2.4.81 has a potential reflected XSS in a quickDelete acti ...)
- NOT-FOR-US: MISP
+ - misp <itp> (bug #1144317)
CVE-2017-15215 (Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticate ...)
- shaarli <not-affected> (Fixed before initial re-upload to the archive)
CVE-2017-15214 (Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an ...)
@@ -799740,7 +799740,7 @@ CVE-2017-14339 (The DNS packet parser in YADIFA before 2.2.6 does not check for
CVE-2017-14338
RESERVED
CVE-2017-14337 (When MISP before 2.4.80 is configured with X.509 certificate authentic ...)
- NOT-FOR-US: MISP (Malware Information Sharing Platform and Threat Sharing)
+ - misp <itp> (bug #1144317)
CVE-2017-14336
RESERVED
CVE-2017-14335 (On Beijing Hanbang Hanbanggaoke devices, because user-controlled input ...)
@@ -801791,7 +801791,7 @@ CVE-2017-13672 (QEMU (aka Quick Emulator), when built with the VGA display emula
NOTE: CentOS7 has a backport/upgrade(?) for their frankenstein version
NOTE: http://vault.centos.org/7.6.1810/updates/Source/SPackages/qemu-kvm-1.5.3-160.el7_6.3.src.rpm
CVE-2017-13671 (app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent ...)
- NOT-FOR-US: MISP (Malware Information Sharing Platform and Threat Sharing)
+ - misp <itp> (bug #1144317)
CVE-2017-13670 (In BlackCat CMS 1.2, remote authenticated users can upload any file vi ...)
NOT-FOR-US: BlackCat CMS
CVE-2017-13669 (SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswere ...)
@@ -821901,7 +821901,7 @@ CVE-2016-10254 (The allocate_elf function in common.h in elfutils before 0.168 a
NOTE: https://blogs.gentoo.org/ago/2016/11/04/elfutils-memory-allocation-failure-in-allocate_elf-common-h/
NOTE: https://git.fedorahosted.org/cgit/elfutils.git/commit/?id=191000fdedba3fafe4d5b8cddad3f3318b49c3fb
CVE-2017-7215 (Cross site scripting in some view elements in the index filter tool in ...)
- NOT-FOR-US: MISP (Malware Information Sharing Platform and Threat Sharing)
+ - misp <itp> (bug #1144317)
CVE-2017-7214 (An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x ...)
- nova 2:14.0.0-4 (bug #858568)
[jessie] - nova <not-affected> (Vulnerable code not present)
@@ -880904,11 +880904,11 @@ CVE-2015-5722 (buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x befo
- bind9 1:9.9.5.dfsg-12
NOTE: https://kb.isc.org/article/AA-01287
CVE-2015-5721 (Malware Information Sharing Platform (MISP) before 2.3.90 allows remot ...)
- NOT-FOR-US: Malware Information Sharing Platform
+ - misp <itp> (bug #1144317)
CVE-2015-5720 (Multiple cross-site scripting (XSS) vulnerabilities in the template-cr ...)
- NOT-FOR-US: Malware Information Sharing Platform
+ - misp <itp> (bug #1144317)
CVE-2015-5719 (app/Controller/TemplatesController.php in Malware Information Sharing ...)
- NOT-FOR-US: Malware Information Sharing Platform
+ - misp <itp> (bug #1144317)
CVE-2015-5718 (Stack-based buffer overflow in the handle_debug_network function in th ...)
NOT-FOR-US: Websense Content Gateway
CVE-2015-5734 (Cross-site scripting (XSS) vulnerability in the legacy theme preview i ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbb044df009a4fe43183803c6a2027dcddffb1f4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbb044df009a4fe43183803c6a2027dcddffb1f4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/4bf4cbde/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list