[Git][security-tracker-team/security-tracker][master] track misp ITP

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 19 16:15:25 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fbb044df by Moritz Muehlenhoff at 2026-08-19T17:13:11+02:00
track misp ITP

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -12597,23 +12597,23 @@ CVE-2026-73211 (PeerTube is an ActivityPub-federated video streaming platform. P
 CVE-2026-73210 (A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo ...)
 	NOT-FOR-US: Lookyloo PlaywrightCapture
 CVE-2026-73162 (Affected versions of MISP cti-transmute expose several state-changing  ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: cti-transmute
 CVE-2026-73161 (Affected versions of cti-transmute improperly handle conversion-table  ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: cti-transmute
 CVE-2026-73160 (Affected versions of cti-transmute contain an SSRF vulnerability in th ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: cti-transmute
 CVE-2026-73159 (Affected versions of cti-transmute allow a tag's icon value to be stor ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: cti-transmute
 CVE-2026-73158 (Affected versions of cti-transmute insufficiently validate saved graph ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: cti-transmute
 CVE-2026-73157 (Affected versions of cti-transmute render data obtained from a remote  ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: cti-transmute
 CVE-2026-73156 (Affected versions of cti-transmute fail to HTML-escape attacker-contro ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: cti-transmute
 CVE-2026-73155 (Affected versions of cti-transmute allow authenticated users to add or ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: cti-transmute
 CVE-2026-73140 (Affected versions of cti-transmute fail to apply comment-level access- ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: cti-transmute
 CVE-2026-73090 (PeerTube is an ActivityPub-federated video streaming platform. Prior t ...)
 	- peertube <itp> (bug #950821)
 CVE-2026-73089 (Browserslist is a configuration tool for sharing target browsers and N ...)
@@ -14874,9 +14874,9 @@ CVE-2026-72862 (Dokploy is a free, self-hostable Platform as a Service (PaaS). P
 CVE-2026-72761 (The webhook URL validator in `website/notifications/webhooks.py` uses  ...)
 	NOT-FOR-US: vulnerability-lookup
 CVE-2026-72760 (Affected versions of MISP cti-transmute disclose users' email addresse ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: cti-transmute
 CVE-2026-72759 (In affected versions of MISP cti-transmute, the conversion-history det ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: cti-transmute
 CVE-2026-72751 (CTI-Transmute is affected by a stored cross-site scripting (XSS) vulne ...)
 	NOT-FOR-US: CTI-Transmute
 CVE-2026-72740 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
@@ -26275,7 +26275,7 @@ CVE-2026-67181 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling v
 	- rust-rouille <unfixed> (bug #1142994)
 	NOTE: https://github.com/theopaid/CVE-2026-67181-HTTP-Request-Smuggling-via-Transfer-Encoding-Desynchronization-rouille-
 CVE-2026-67178 (MISP installation scripts generated an Apache HTTP virtual-host config ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: MISP installation scripts
 CVE-2026-67174 (Pivotick contains a DOM-based cross-site scripting vulnerability in it ...)
 	NOT-FOR-US: Pivotick
 CVE-2026-67173 (Pivotick did not validate the URL scheme of node imagePath values deri ...)
@@ -42811,7 +42811,7 @@ CVE-2026-6541 (Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <
 CVE-2026-62147 (The Tempo Operator's gateway component failed to consistently apply na ...)
 	NOT-FOR-US: Red Hat Tempo Operator
 CVE-2026-62143 (A Server-Side Request Forgery (SSRF) protection bypass existed in the  ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: MISP addon
 CVE-2026-61985 (Missing Authorization vulnerability in magepeopleteam Car Rental Manag ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61983 (Missing Authorization vulnerability in andy_moyle Church Admin church- ...)
@@ -44703,7 +44703,7 @@ CVE-2026-7558 (The Age Verification & Identity Verification by Token of Trust pl
 CVE-2026-6910 (The Bookero.pl \u2013 system rezerwacji online plugin for WordPress is ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-61474 (An improper authorization check in MISP\u2019s attribute creation endp ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-61344 (The Superior Court of California Hearing Reminder Service at https://w ...)
 	NOT-FOR-US: Superior Court of California Hearing Reminder Service
 CVE-2026-61343 (LibreBooking's email template editor save action passes the submitted  ...)
@@ -45586,9 +45586,9 @@ CVE-2026-6280 (Exposure of sensitive information due to incompatible policies vu
 CVE-2026-6230 (The Tainacan plugin for WordPress is vulnerable to time-based blind SQ ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-60125 (MISP\u2019s importModule() path used getEnabledModule() to resolve a s ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-60124 (An authorization bypass in MISP\u2019s EventsController::importModule( ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-60102 (Horde Virtual File System (VFS) API before 3.0.1 contains an OS comman ...)
 	- php-horde-vfs <unfixed> (bug #1143051)
 	[bookworm] - php-horde-vfs <end-of-life> (EOL in bookworm LTS)
@@ -59232,17 +59232,17 @@ CVE-2026-56450 (AIL did not restrict repeated failed attempts to verify a two-fa
 CVE-2026-56448 (A path traversal vulnerability exists in AIL Framework before the rele ...)
 	NOT-FOR-US: AIL framework
 CVE-2026-56447 (MISP allowed an authenticated site administrator to set the Kafka_rdka ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-56446 (MISP allowed a site administrator to configure an arbitrary filesystem ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-56425 (The Azure Active Directory (AAD) authentication implementation contain ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-56424 (MISP core contained multiple broken access-control flaws where authori ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-56423 (MISP Core contained broken access-control checks in the bulk deletion  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-56422 (Multiple MISP core controllers and model capture paths accepted client ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-56109 (The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 c ...)
 	- alsa-lib 1.2.16.1-1 (unimportant)
 	NOTE: https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/
@@ -64228,29 +64228,29 @@ CVE-2026-9061 (The Store Locator WordPress plugin before 1.6.9 does not sanitize
 CVE-2026-6676 (Heap buffer out-of-bounds write vulnerability in Avira Antivirus engin ...)
 	NOT-FOR-US: Avira
 CVE-2026-54398 (An authorization flaw in MISP\u2019s object add/edit handling allowed  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54397 (A vulnerability in MISP\u2019s non-REST event editing path allowed an  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54396 (An information disclosure vulnerability exists in the MISP AuthKey edi ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54395 (MISP contains a reflected cross-site scripting vulnerability in the Ui ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54394 (MISP contains a path traversal vulnerability in OrganisationsControlle ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54393 (A stored cross-site scripting vulnerability exists in MISP when the Ov ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54362 (An incorrect visibility condition in the MISP event template builder a ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54361 (MISP contained multiple mass assignment vulnerabilities in the handlin ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54360 (A mass assignment vulnerability exists in MISP\u2019s sharing group cr ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54359 (MISP contains an insecure default configuration in which the Security. ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54358 (An incorrect authorization vulnerability in MISP allows an organizatio ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54357 (An improper authorization vulnerability in MISP allowed an authenticat ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-54231 (A content injection vulnerability was found in the ABRT post-create ev ...)
 	NOT-FOR-US: abrt/libreport
 CVE-2026-54230 (A symlink following vulnerability was found in the ABRT post-create ev ...)
@@ -65660,7 +65660,7 @@ CVE-2026-53698 (Silverpeas through 6.4.6 mishandles the "Personal space" feature
 CVE-2026-53694 (Improper Neutralization of Argument Delimiters in a Command ('Argument ...)
 	NOT-FOR-US: Nomachine
 CVE-2026-53693 (A stored cross-site scripting vulnerability existed in MISPBSimVis tag ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: BSimVis
 CVE-2026-53689 (libnfs through 6.0.2 before 55c18ea does not validate a string size, l ...)
 	{DLA-4689-1}
 	- libnfs 5.0.2-1.1 (bug #1139731)
@@ -71389,21 +71389,21 @@ CVE-2026-22054 (Active IQ Config Advisor version 6.7.3 contains hard-coded crede
 CVE-2026-10880 (OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the l ...)
 	NOT-FOR-US: OSNexus QuantaStor SDS Manager
 CVE-2026-10868 (A mass assignment vulnerability exists in the MISP user edit functiona ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-10864 (A vulnerability in the MISP dashboard widgets allowed an authenticated ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-10863 (A security issue was fixed in the correlations over-correlation endpoi ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-10861 (An open redirect vulnerability existed in MISP UsersController::routea ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-10860 (A logic error in the MISP CRUD component delete handler allowed valida ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-10856 (A URL validation flaw in the MISP dashboard button widget allowed a cr ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-10855 (An authorization flaw existed in the MISP Event Template Importer over ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-10854 (A visibility control issue in the event template creation workflow all ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-10843 (A flaw was found in the OpenShift Cloud Credential Operator Mint-mode  ...)
 	NOT-FOR-US: Red Hat OpenShift
 CVE-2026-10840 (A flaw was found in the OpenShift Pipelines operator. The tekton-sched ...)
@@ -72603,7 +72603,7 @@ CVE-2026-10622 (Improper Authentication in REST API in Collibra Agent, allows a
 CVE-2026-10621 (Path traversal in restore handler in Collibra Agent, allows an attacke ...)
 	NOT-FOR-US: Collibra Agent
 CVE-2026-10611 (An authentication bypass vulnerability exists in MISP when LDAP mixed  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-10606 (A vulnerability was determined in DedeCMS 5.7.88. The affected element ...)
 	NOT-FOR-US: DedeCMS
 CVE-2026-10591 (Insufficient access control restrictions in the file write tool in Ama ...)
@@ -81644,9 +81644,9 @@ CVE-2026-9141 (Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an
 CVE-2026-9139 (Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-c ...)
 	NOT-FOR-US: Taiko AG1000-01A SMS Alert Gateway
 CVE-2026-9137 (The CSP report endpoint in MISP intended to limit logged CSP reports t ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-9136 (A vulnerability was identified in the ShadowAttribute proposal creatio ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-9133 (Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws ...)
 	NOT-FOR-US: Amazon
 CVE-2026-9129 (A path traversal vulnerability exists in the Altium Enterprise Server  ...)
@@ -81950,7 +81950,7 @@ CVE-2026-9100 (The MongoDB C Driver's legacy GridFS API accepts malformed file m
 CVE-2026-9087 (A flaw was found in Keycloak. The cross-session verification proof is  ...)
 	- keycloak <itp> (bug #1088287)
 CVE-2026-9084 (MISP\u2019s OIDC authentication plugin allowed automatic linking of an ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-9065 (SureCart version prior to 4.2.1 are vulnerable to authenticated SQL in ...)
 	NOT-FOR-US: SureCart
 CVE-2026-9064 (A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...)
@@ -85251,11 +85251,11 @@ CVE-2026-44423 (ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api
 CVE-2026-44418 (EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlie ...)
 	NOT-FOR-US: EcclesiaCRM
 CVE-2026-44381 (MISP is an open source threat intelligence and sharing platform. Prior ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-44380 (MISP is an open source threat intelligence and sharing platform. Prior ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-44379 (MISP is an open source threat intelligence and sharing platform. Prior ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-44377 (CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authent ...)
 	NOT-FOR-US: CubeCart
 CVE-2026-44376 (CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthe ...)
@@ -85269,9 +85269,9 @@ CVE-2026-44369 (CVAT is an open source interactive video and image annotation to
 CVE-2026-44368 (PyQuorum is a cryptographic library for secret sharing and key managem ...)
 	NOT-FOR-US: PyQuorum
 CVE-2026-44364 (MISP modules are autonomous modules that can be used to extend MISP fo ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: MISP modules
 CVE-2026-44363 (MISP modules are autonomous modules that can be used to extend MISP fo ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: MISP modules
 CVE-2026-44351 (fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6 ...)
 	NOT-FOR-US: fast-jwt
 CVE-2026-44295 (protobufjs-cli is the command line add-on for protobuf.js. Prior to 1. ...)
@@ -90635,7 +90635,7 @@ CVE-2026-8083 (A vulnerability was found in SourceCodester Pharmacy Sales and In
 CVE-2026-8081 (A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Af ...)
 	NOT-FOR-US: CLIProxyAPI
 CVE-2026-8080 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-7821 (Improper certificate validation in Ivanti EPMM beforeversions 12.6.1.1 ...)
 	NOT-FOR-US: Ivanti
 CVE-2026-7415 (The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to all ...)
@@ -106869,7 +106869,7 @@ CVE-2026-39974 (n8n-MCP is a Model Context Protocol (MCP) server that provides A
 CVE-2026-39972 (Mercure is a protocol for pushing data updates to web browsers and oth ...)
 	NOT-FOR-US: Mercure
 CVE-2026-39962 (MISP is an open source threat intelligence and sharing platform. Prior ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2026-39961 (Aiven Operator allows you to provision and manage Aiven Services from  ...)
 	NOT-FOR-US: Aiven Operator
 CVE-2026-39959 (Tmds.DBus provides .NET libraries for working with D-Bus from .NET. Tm ...)
@@ -161498,7 +161498,7 @@ CVE-2023-36337 (A reflected cross-site scripting (XSS) vulnerability in the comp
 CVE-2025-67907
 	REJECTED
 CVE-2025-67906 (In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp a ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2025-67901 (openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other p ...)
 	NOT-FOR-US: openrsync
 CVE-2025-67900 (NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF  ...)
@@ -168562,11 +168562,11 @@ CVE-2025-12143 (Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbo
 CVE-2025-11156 (Netskope was notified about a potential gap in its agent (NS Client) o ...)
 	NOT-FOR-US: Netskope
 CVE-2025-66386 (app/Model/EventReport.php in MISP before 2.5.27 allows path traversal  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2025-66385 (UsersController::edit in Cerebrate before 1.30 allows an authenticated ...)
 	NOT-FOR-US: Cerebrate
 CVE-2025-66384 (app/Controller/EventsController.php in MISP before 2.5.24 has invalid  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2025-66382 (In libexpat through 2.7.3, a crafted file with an approximate size of  ...)
 	- expat <unfixed> (bug #1121543)
 	[trixie] - expat <postponed> (Minor issue, revisit when fixed upstream)
@@ -248917,11 +248917,11 @@ CVE-2024-7577 (IBM InfoSphere Information Server 11.7 could disclose sensitive u
 CVE-2024-6875 (A vulnerability was found in the Infinispan component in Red Hat Data  ...)
 	NOT-FOR-US: Infinispan component in Red Hat Data Grid
 CVE-2024-58130 (In app/Controller/Component/RestResponseComponent.php in MISP before 2 ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-58129 (In MISP before 2.4.193, menu_custom_right_link_html parameters can be  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-58128 (In MISP before 2.4.193, menu_custom_right_link parameters can be set v ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-57083 (A prototype pollution in the component Module.mergeObjects (redoc/bund ...)
 	NOT-FOR-US: redoc
 CVE-2024-56975 (InvoicePlane (all versions tested as of December 2024) v.1.6.11 and be ...)
@@ -264357,7 +264357,7 @@ CVE-2024-9601 (The Qubely \u2013 Advanced Gutenberg Blocks plugin for WordPress
 CVE-2024-7052 (The Forminator Forms  WordPress plugin before 1.38.3 does not sanitise ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-57969 (app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-57782 (An issue in Docker-proxy v18.09.0 allows attackers to cause a denial o ...)
 	NOTE: Bogus report for possinly the use of a proxy in a very old Docker release
 CVE-2024-57378 (Wazuh SIEM version 4.8.2 is affected by a broken access control vulner ...)
@@ -285251,9 +285251,9 @@ CVE-2023-50913 (Oxide control plane software before 5 allows SSRF.)
 CVE-2023-48010 (STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism ...)
 	NOT-FOR-US: STMicroelectronics SPC58
 CVE-2024-54675 (app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2. ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-54674 (app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-54221 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-54014 (Improper authorization in handler for custom URL scheme issue in 'Skyl ...)
@@ -307820,7 +307820,7 @@ CVE-2024-1578 (The MiCard PLUS Ci and MiCard PLUS BLE reader products developed
 CVE-2024-8869 (A vulnerability classified as critical has been found in TOTOLINK A720 ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2024-46918 (app/Controller/UserLoginProfilesController.php in MISP before 2.4.198  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-44059 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-44058 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
@@ -310909,7 +310909,7 @@ CVE-2024-45527 (REDCap 14.7.0 allows HTML injection via the project title of a N
 CVE-2024-45522 (Linen before cd37c3e does not verify that the domain is linen.dev or w ...)
 	NOT-FOR-US: Linen
 CVE-2024-45509 (In MISP through 2.4.196, app/Controller/BookmarksController.php does n ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-45508 (HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ...)
 	- htmldoc 1.9.18-2 (bug #1081236)
 	[bookworm] - htmldoc <no-dsa> (Minor issue)
@@ -360747,9 +360747,9 @@ CVE-2024-29864 (Distrobox before 1.7.0.1 allows attackers to execute arbitrary c
 CVE-2024-29862 (The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4. ...)
 	NOT-FOR-US: Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder
 CVE-2024-29859 (In MISP before 2.4.187, add_misp_export in app/Controller/EventsContro ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-29858 (In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsCo ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-29474 (OneBlog v2.3.4 was discovered to contain a stored cross-site scripting ...)
 	NOT-FOR-US: OneBlog
 CVE-2024-29473 (OneBlog v2.3.4 was discovered to contain a stored cross-site scripting ...)
@@ -371475,9 +371475,9 @@ CVE-2024-25678 (In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation
 CVE-2024-25677 (In Min before 1.31.0, local files are not correctly treated as unique  ...)
 	NOT-FOR-US: Min
 CVE-2024-25675 (An issue was discovered in MISP before 2.4.184. A client does not need ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-25674 (An issue was discovered in MISP before 2.4.184. Organisation logo uplo ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2024-25454 (Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference ...)
 	NOT-FOR-US: Bento4
 CVE-2024-25453 (Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference ...)
@@ -382036,7 +382036,7 @@ CVE-2023-6553 (The Backup Migration plugin for WordPress is vulnerable to Remote
 CVE-2023-5310 (A denial of service vulnerability exists in all Silicon Labs Z-Wave co ...)
 	NOT-FOR-US: Silicon Labs Z-Wavecontroller and endpoint devices running Z-Wave SDK
 CVE-2023-50918 (app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandl ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-50917 (MajorDoMo (aka Major Domestic Module) before 0662e5e allows command ex ...)
 	NOT-FOR-US: MajorDoMo (aka Major Domestic Module)
 CVE-2023-50871 (In JetBrains YouTrack before 2023.3.22268 authorization check for inli ...)
@@ -385297,7 +385297,7 @@ CVE-2023-6474 (A vulnerability has been found in PHPGurukul Nipah Virus Testing
 CVE-2023-6473 (A vulnerability, which was classified as problematic, was found in Sou ...)
 	NOT-FOR-US: SourceCodester Online Quiz System
 CVE-2023-49926 (app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-47100
 	REJECTED
 CVE-2023-6472 (A vulnerability, which was classified as problematic, has been found i ...)
@@ -387322,15 +387322,15 @@ CVE-2023-6020 (LFI in Ray's /static/ directory allows attackers to read any file
 CVE-2023-6014 (An attacker is able to arbitrarily create an account in MLflow bypassi ...)
 	NOT-FOR-US: mlflow
 CVE-2023-48659 (An issue was discovered in MISP before 2.4.176. app/Controller/AppCont ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-48658 (An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-48657 (An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-48656 (An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-48655 (An issue was discovered in MISP before 2.4.176. app/Controller/Compone ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-48649 (Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on t ...)
 	NOT-FOR-US: Concrete CMS
 CVE-2023-48648 (Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized ac ...)
@@ -401837,7 +401837,7 @@ CVE-2023-41104 (libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x
 CVE-2023-41100 (An issue was discovered in the hcaptcha (aka hCaptcha for EXT:form) ex ...)
 	NOT-FOR-US: TYPO3 extension
 CVE-2023-41098 (An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsC ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-40370 (IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vuln ...)
 	NOT-FOR-US: IBM
 CVE-2023-40282 (Improper authentication vulnerability in Rakuten WiFi Pocket all versi ...)
@@ -403083,7 +403083,7 @@ CVE-2023-40253 (Improper Authentication vulnerability in Genians Genian NAC V4.0
 CVE-2023-40235 (An NTLM Hash Disclosure was discovered in ArchiMate Archi before 5.1.0 ...)
 	NOT-FOR-US: ArchiMate Archi
 CVE-2023-40224 (MISP 2.4.174 allows XSS in app/View/Events/index.ctp.)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-40014 (OpenZeppelin Contracts is a library for secure smart contract developm ...)
 	NOT-FOR-US: OpenZeppelin Contracts
 CVE-2023-3824 (In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* bef ...)
@@ -409003,9 +409003,9 @@ CVE-2023-37360 (pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript
 	NOTE: https://github.com/manugarg/pacparser/security/advisories/GHSA-62q6-v997-f7v9
 	NOTE: https://github.com/manugarg/pacparser/commit/0bf0636de624996fe202b51eec8a58abd774269e (v1.4.2)
 CVE-2023-37307 (In MISP before 2.4.172, title_for_layout is not properly sanitized in  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-37306 (MISP 2.4.172 mishandles different certificate file extensions in serve ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-37305 (An issue was discovered in the ProofreadPage (aka Proofread Page) exte ...)
 	NOT-FOR-US: MediaWiki extension ProofreadPage
 CVE-2023-37304 (An issue was discovered in the DoubleWiki extension for MediaWiki thro ...)
@@ -422369,7 +422369,7 @@ CVE-2023-28886
 CVE-2023-28885 (The MyLink infotainment system (build 2021.3.26) in General Motors Che ...)
 	NOT-FOR-US: MyLink infotainment system
 CVE-2023-28884 (In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-28883 (In Cerebrate 1.13, a blind SQL injection exists in the searchAll API e ...)
 	NOT-FOR-US: Cerebrate
 CVE-2023-28882 (Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial ...)
@@ -423487,9 +423487,9 @@ CVE-2015-10096 (A vulnerability, which was classified as critical, was found in
 CVE-2023-28608
 	RESERVED
 CVE-2023-28607 (js/event-graph.js in MISP before 2.4.169 allows XSS via the event-grap ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-28606 (js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph no ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-28605
 	RESERVED
 CVE-2023-28604 (The fluid_components (aka Fluid Components) extension before 3.5.0 for ...)
@@ -431059,9 +431059,9 @@ CVE-2023-26057 (An XXE issue was discovered in Nokia NetAct before 22 FP2211 via
 CVE-2023-0920
 	RESERVED
 CVE-2022-48329 (MISP before 2.4.166 unsafely allows users to use the order parameter,  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-48328 (app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.1 ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-4325 (A vulnerability, which was classified as problematic, has been found i ...)
 	NOT-FOR-US: NHN TOAST UI Chart
 CVE-2017-20179 (A vulnerability was found in InSTEDD Pollit 2.3.1. It has been rated a ...)
@@ -437287,7 +437287,7 @@ CVE-2023-24072
 CVE-2023-24071
 	RESERVED
 CVE-2023-24070 (app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an X ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-24069 (Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an att ...)
 	- signal-desktop <itp> (bug #842943)
 CVE-2023-24068 (Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an att ...)
@@ -437438,11 +437438,11 @@ CVE-2023-24030 (An open redirect vulnerability exists in the /preauth Servlet in
 CVE-2023-24029 (In Progress WS_FTP Server before 8.8, it is possible for a host admini ...)
 	NOT-FOR-US: Progress WS_FTP Server
 CVE-2023-24028 (In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorre ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-24027 (In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a netwo ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-24026 (In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerabilit ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2023-24025 (CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2 ...)
 	NOT-FOR-US: CRYSTALS-DILITHIUM
 CVE-2023-24024
@@ -444167,7 +444167,7 @@ CVE-2022-47929 (In the Linux kernel before 6.1.6, a NULL pointer dereference bug
 	- linux 6.1.7-1
 	NOTE: https://git.kernel.org/linus/96398560f26aa07e8f2969d73c8197e6a6d10407 (6.2-rc4)
 CVE-2022-47928 (In MISP before 2.4.167, there is XSS in the template file uploads in a ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-47927 (An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.3 ...)
 	{DLA-3489-1}
 	- mediawiki 1:1.39.1-1
@@ -463952,7 +463952,7 @@ CVE-2022-42726
 CVE-2022-42725 (Warpinator through 1.2.14 allows access outside of an intended directo ...)
 	NOT-FOR-US: Warpinator
 CVE-2022-42724 (app/Controller/UsersController.php in MISP before 2.4.164 allows attac ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-42723
 	RESERVED
 CVE-2022-42722 (In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers ...)
@@ -500789,19 +500789,19 @@ CVE-2022-29536 (In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML docu
 CVE-2022-29535 (Zoho ManageEngine OPManager through 125588 allows SQL Injection via a  ...)
 	NOT-FOR-US: Zoho ManageEngine
 CVE-2022-29534 (An issue was discovered in MISP before 2.4.158. In UsersController.php ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-29533 (An issue was discovered in MISP before 2.4.158. There is XSS in app/Co ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-29532 (An issue was discovered in MISP before 2.4.158. There is XSS in the ce ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-29531 (An issue was discovered in MISP before 2.4.158. There is stored XSS in ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-29530 (An issue was discovered in MISP before 2.4.158. There is stored XSS in ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-29529 (An issue was discovered in MISP before 2.4.158. There is stored XSS vi ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-29528 (An issue was discovered in MISP before 2.4.158. PHAR deserialization c ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-1419 (The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_ ...)
 	{DSA-5173-1}
 	- linux 5.5.13-1
@@ -507543,13 +507543,13 @@ CVE-2022-27248 (A directory traversal vulnerability in IdeaRE RefTree before 202
 CVE-2022-27247 (onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an att ...)
 	NOT-FOR-US: cdSoft Winhotel.MX
 CVE-2022-27246 (An issue was discovered in MISP before 2.4.156. An SVG org logo (which ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-27245 (An issue was discovered in MISP before 2.4.156. app/Model/Server.php d ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-27244 (An issue was discovered in MISP before 2.4.156. A malicious site admin ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-27243 (An issue was discovered in MISP before 2.4.156. app/View/Users/terms.c ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2022-27242 (A vulnerability has been identified in OpenV2G (V0.9.4). The OpenV2G E ...)
 	NOT-FOR-US: OpenV2G / Siemens
 CVE-2022-27241 (A vulnerability has been identified in Mendix Applications using Mendi ...)
@@ -542217,7 +542217,7 @@ CVE-2021-41328
 CVE-2021-41327
 	RESERVED
 CVE-2021-41326 (In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles p ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-41325 (Broken access control for user creation in Pydio Cells 2.2.9 allows re ...)
 	NOT-FOR-US: Pydio Cells
 CVE-2021-41324 (Directory traversal in the Copy, Move, and Delete features in Pydio Ce ...)
@@ -547400,7 +547400,7 @@ CVE-2020-36474 (SafeCurl before 0.9.2 has a DNS rebinding vulnerability.)
 CVE-2021-39303 (The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka P ...)
 	NOT-FOR-US: Jamf Pro
 CVE-2021-39302 (MISP 2.4.148, in certain configurations, allows SQL injection via the  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-39301 (Potential vulnerabilities have been identified in UEFI firmware (BIOS) ...)
 	NOT-FOR-US: HP
 CVE-2021-39300 (Potential vulnerabilities have been identified in UEFI firmware (BIOS) ...)
@@ -551591,9 +551591,9 @@ CVE-2021-37745
 CVE-2021-37744
 	RESERVED
 CVE-2021-37743 (app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored X ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-37742 (app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.14 ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-37741 (ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vul ...)
 	NOT-FOR-US: ManageEngine
 CVE-2021-37740 (A denial of service vulnerability exists in MDT's firmware for the KNX ...)
@@ -552141,7 +552141,7 @@ CVE-2021-37536
 CVE-2021-37535 (SAP NetWeaver Application Server Java (JMS Connector Service) - versio ...)
 	NOT-FOR-US: SAP
 CVE-2021-37534 (app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-37533 (Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host fr ...)
 	{DSA-5307-1 DLA-3251-1}
 	- libcommons-net-java 3.9.0-1 (bug #1025910)
@@ -555266,7 +555266,7 @@ CVE-2021-36213 (HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 defa
 	NOTE: https://discuss.hashicorp.com/t/hcsec-2021-16-consul-s-application-aware-intentions-deny-action-fails-open-when-combined-with-default-deny-policy/26855
 	NOTE: https://github.com/hashicorp/consul/pull/10619
 CVE-2021-36212 (app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored X ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-3637 (A flaw was found in keycloak-model-infinispan in keycloak versions bef ...)
 	- keycloak <itp> (bug #1088287)
 CVE-2021-36211
@@ -557070,7 +557070,7 @@ CVE-2021-35504 (Afian FileRun 2021.03.26 allows Remote Code Execution (by admini
 CVE-2021-35503 (Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For ...)
 	NOT-FOR-US: Afian FileRun
 CVE-2021-35502 (app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-3622 (A flaw was found in the hivex library. This flaw allows an attacker to ...)
 	- hivex 1.3.21-1 (bug #991860)
 	[bullseye] - hivex <no-dsa> (Minor issue)
@@ -566787,7 +566787,7 @@ CVE-2021-31782
 CVE-2021-31781
 	RESERVED
 CVE-2021-31780 (In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing grou ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-31779 (The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows  ...)
 	NOT-FOR-US: Typo3 extension
 CVE-2021-31778 (The media2click (aka 2 Clicks for External Media) extension 1.x before ...)
@@ -576993,7 +576993,7 @@ CVE-2021-27905 (The ReplicationHandler (normally registered at "/replication" un
 	NOTE: https://lists.apache.org/thread.html/r0ddc3a82bd7523b1453cb7a5e09eb5559517145425074a42eb326b10%40%3Cannounce.apache.org%3E
 	NOTE: Server components disabled in 3.6.2+dfsg-23, using that as the fixed version
 CVE-2021-27904 (An issue was discovered in app/Model/SharingGroupServer.php in MISP 2. ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-27903 (An issue was discovered in Craft CMS before 3.6.7. In some circumstanc ...)
 	NOT-FOR-US: Craft CMS
 CVE-2021-27902 (An issue was discovered in Craft CMS before 3.6.0. In some circumstanc ...)
@@ -583402,7 +583402,7 @@ CVE-2020-36195 (An SQL injection vulnerability has been reported to affect QNAP
 CVE-2020-36194 (An XSS vulnerability has been reported to affect QNAP NAS running QTS  ...)
 	NOT-FOR-US: QNAP
 CVE-2021-3184 (MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-3183 (Files.com Fat Client 3.3.6 allows authentication bypass because the cl ...)
 	NOT-FOR-US: Files.com Fat Client
 CVE-2021-3182 (D-Link DCS-5220 devices have a buffer overflow. NOTE: This vulnerabili ...)
@@ -583432,11 +583432,11 @@ CVE-2021-25327 (Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-sit
 CVE-2021-25326 (Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrec ...)
 	NOT-FOR-US: Skyworth Digital Technology RN510
 CVE-2021-25325 (MISP 2.4.136 has XSS via galaxy cluster element values to app/View/Gal ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-25324 (MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster n ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-25323 (The default setting of MISP 2.4.136 did not enable the requirements (a ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2021-25322 (A UNIX Symbolic Link (Symlink) Following vulnerability in python-Hyper ...)
 	- hyperkitty <not-affected> (SuSE-specific packaging issue)
 CVE-2021-25321 (A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of  ...)
@@ -600990,7 +600990,7 @@ CVE-2020-29573 (sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6
 	NOTE: Fixed by: https://sourceware.org/git/?p=glibc.git;h=d81f90ccd0109de9ed78aeeb8d86e2c6d4600690 (glibc-2.22)
 	NOTE: Fixed by: https://sourceware.org/git/?p=glibc.git;h=8df4e219e43a4a257d0759b54fef8c488e2f282e (glibc-2.23)
 CVE-2020-29572 (app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-29571 (An issue was discovered in Xen through 4.14.x. A bounds check common t ...)
 	{DSA-4812-1}
 	- xen 4.14.0+88-g1d1d1f5391-1
@@ -602528,7 +602528,7 @@ CVE-2020-29007 (The Score extension through 0.3.0 for MediaWiki has a remote cod
 	NOTE: https://phabricator.wikimedia.org/T257062
 	NOTE: https://www.mediawiki.org/wiki/Extension:Score/2021_security_advisory
 CVE-2020-29006 (MISP before 2.4.135 lacks an ACL check, related to app/Controller/Gala ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-29005 (The API in the Push extension for MediaWiki through 1.35 used cleartex ...)
 	NOT-FOR-US: Push extension for MediaWiki
 CVE-2020-29004 (The API in the Push extension for MediaWiki through 1.35 did not requi ...)
@@ -602715,7 +602715,7 @@ CVE-2020-28948 (Archive_Tar through 1.4.10 allows an unserialization attack beca
 	NOTE: https://github.com/pear/Archive_Tar/commit/0670a05fdab997036a3fc3ef113b8f5922e574da
 	NOTE: https://www.drupal.org/sa-core-2020-013
 CVE-2020-28947 (In MISP 2.4.134, XSS exists in the template element index view because ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-28946 (An improper webserver configuration on Plum IK-401 devices with firmwa ...)
 	NOT-FOR-US: Plum IK-401 devices
 CVE-2020-28945 (OX App Suite 7.10.4 and earlier allows XSS via crafted content to reac ...)
@@ -607711,7 +607711,7 @@ CVE-2020-28045 (An unsigned-library issue was discovered in ProlinOS through 2.4
 CVE-2020-28044 (An attacker with physical access to a PAX Point Of Sale device with Pr ...)
 	NOT-FOR-US: ProlinOS
 CVE-2020-28043 (MISP through 2.4.133 allows SSRF in the REST client via the use_full_p ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-28042 (ServiceStack before 5.9.2 mishandles JWT signature verification unless ...)
 	NOT-FOR-US: ServiceStack
 CVE-2020-28041 (The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 ...)
@@ -614018,7 +614018,7 @@ CVE-2020-25768 (Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10
 CVE-2020-25767 (An issue was discovered in HCC Embedded NicheStack IPv4 4.1. The dnc_c ...)
 	NOT-FOR-US: HCC Embedded NicheStack
 CVE-2020-25766 (An issue was discovered in MISP before 2.4.132. It can perform an unwa ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-25765 (Addressed remote code execution vulnerability in reg_device.php due to ...)
 	NOT-FOR-US: Western Digital My Cloud Devices
 CVE-2020-25764
@@ -618258,7 +618258,7 @@ CVE-2020-24087
 CVE-2020-24086
 	RESERVED
 CVE-2020-24085 (A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-24084
 	RESERVED
 CVE-2020-24083
@@ -636555,7 +636555,7 @@ CVE-2020-15713 (rConfig 3.9.5 is vulnerable to SQL injection. A remote authentic
 CVE-2020-15712 (rConfig 3.9.5 could allow a remote authenticated attacker to traverse  ...)
 	NOT-FOR-US: rConfig
 CVE-2020-15711 (In MISP before 2.4.129, setting a favourite homepage was not CSRF prot ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-15710 (Potential double free in Bluez 5 module of PulseAudio could allow a lo ...)
 	- pulseaudio <not-affected> (Issue in Ubuntu-specific patch)
 	NOTE: https://bugs.launchpad.net/ubuntu/%2Bsource/pulseaudio/%2Bbug/1884738
@@ -637433,9 +637433,9 @@ CVE-2020-15414
 CVE-2020-15413
 	RESERVED
 CVE-2020-15412 (An issue was discovered in MISP 2.4.128. app/Controller/EventsControll ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-15411 (An issue was discovered in MISP 2.4.128. app/Controller/AttributesCont ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-15410
 	RESERVED
 CVE-2020-15409
@@ -638552,7 +638552,7 @@ CVE-2020-14971 (Pi-hole through 5.0 allows code injection in piholedhcp (the Sta
 CVE-2020-14970
 	RESERVED
 CVE-2020-14969 (app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribu ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-14968 (An issue was discovered in the jsrsasign package before 8.0.17 for Nod ...)
 	NOT-FOR-US: jsrsasign
 CVE-2020-14967 (An issue was discovered in the jsrsasign package before 8.0.18 for Nod ...)
@@ -643737,7 +643737,7 @@ CVE-2020-13155 (clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML
 CVE-2020-13154 (Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-priv ...)
 	NOT-FOR-US: Zoho
 CVE-2020-13153 (app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-13152 (A remote user can create a specially crafted M3U file, media playlist  ...)
 	- amarok <removed> (unimportant)
 	NOTE: Elevated resource usage in client application, no security impact
@@ -644314,7 +644314,7 @@ CVE-2020-12891 (AMD Radeon Software may be vulnerable to DLL Hijacking through p
 CVE-2020-12890 (Improper handling of pointers in the System Management Mode (SMM) hand ...)
 	NOT-FOR-US: AMD
 CVE-2020-12889 (MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across us ...)
-	NOT-FOR-US: MISP
+	NOT-FOR-US: MISP-maltego
 CVE-2020-12888 (The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles atte ...)
 	{DLA-2420-1 DLA-2385-1}
 	- linux 5.8.7-1
@@ -649441,7 +649441,7 @@ CVE-2020-11460
 CVE-2020-11459
 	RESERVED
 CVE-2020-11458 (app/Model/feed.php in MISP before 2.4.124 allows administrators to cho ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-11457 (pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php ...)
 	NOT-FOR-US: pfSense
 CVE-2020-11456 (LimeSurvey before 4.1.12+200324 has stored XSS in application/views/ad ...)
@@ -652916,9 +652916,9 @@ CVE-2020-10249 (BWA DiREX-Pro 1.2181 devices allow full path disclosure via an i
 CVE-2020-10248 (BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwo ...)
 	NOT-FOR-US: BWA DiREX-Pro devices
 CVE-2020-10247 (MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-10246 (MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-10245 (CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control run ...)
 	NOT-FOR-US: CODESYS
 CVE-2020-10244 (JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.)
@@ -656188,15 +656188,15 @@ CVE-2020-8896 (A Buffer Overflow vulnerability in the khcrypt implementation in
 CVE-2020-8895 (Untrusted Search Path vulnerability in the windows installer of Google ...)
 	NOT-FOR-US: windows installer of Google Earth Pro
 CVE-2020-8894 (An issue was discovered in MISP before 2.4.121. ACLs for discussion th ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-8893 (An issue was discovered in MISP before 2.4.121. The Galaxy view contai ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-8892 (An issue was discovered in MISP before 2.4.121. It did not consider th ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-8891 (An issue was discovered in MISP before 2.4.121. It did not canonicaliz ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-8890 (An issue was discovered in MISP before 2.4.121. It mishandled time ske ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2020-8889 (The ShipStation.com plugin 1.0 for CS-Cart allows remote attackers to  ...)
 	NOT-FOR-US: CS-Cart plugin
 CVE-2020-8888
@@ -675800,7 +675800,7 @@ CVE-2019-19381 (oauth/oauth2/v1/saml/ in Abacus OAuth Login 2019_01_r4_20191021_
 CVE-2019-19380
 	RESERVED
 CVE-2019-19379 (In app/Controller/TagsController.php in MISP 2.4.118, users can bypass ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2019-19378 (In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image  ...)
 	- linux <unfixed> (unimportant)
 	NOTE: raid 5/6 is marked as not production ready for btrfs
@@ -688220,7 +688220,7 @@ CVE-2019-16204 (Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and
 CVE-2019-16203 (Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the ...)
 	NOT-FOR-US: Brocade Fabric OS
 CVE-2019-16202 (MISP before 2.4.115 allows privilege escalation in certain situations. ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2019-16201 (WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5 ...)
 	{DSA-4587-1 DSA-4586-1 DLA-3408-1 DLA-2330-1 DLA-2027-1 DLA-2007-1}
 	- ruby2.5 2.5.7-1
@@ -694918,7 +694918,7 @@ CVE-2019-14287 (In Sudo before 1.8.28, an attacker with access to a Runas ALL su
 	NOTE: Fix test regression: https://www.sudo.ws/repos/sudo/rev/db06a8336c09
 	NOTE: Patch: https://www.openwall.com/lists/oss-security/2019/10/15/2 (1.8.5, 1.8.10)
 CVE-2019-14286 (In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnera ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2019-14285
 	RESERVED
 CVE-2015-9288 (The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allo ...)
@@ -699842,7 +699842,7 @@ CVE-2019-12870 (An issue was discovered in PHOENIX CONTACT PC Worx through 1.86,
 CVE-2019-12869 (An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Wo ...)
 	NOT-FOR-US: PHOENIX CONTACT PC Worx
 CVE-2019-12868 (app/Model/Server.php in MISP 2.4.109 allows remote command execution b ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2019-12867 (Certain actions could cause privilege escalation for issue attachments ...)
 	NOT-FOR-US: JetBrains YouTrack
 CVE-2019-12866 (An Insecure Direct Object Reference, with Authorization Bypass through ...)
@@ -700065,7 +700065,7 @@ CVE-2009-5157 (On Linksys WAG54G2 1.00.10 devices, there is authenticated comman
 CVE-2009-5156 (An issue was discovered on ASMAX AR-804gu 66.34.1 devices. There is Co ...)
 	NOT-FOR-US: ASMAX AR-804gu 66.34.1 devices
 CVE-2019-12794 (An issue was discovered in MISP 2.4.108. Organization admins could res ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2019-XXXX [security issues fixed in 1.8.5]
 	- rdesktop 1.8.6-1 (bug #930387)
 	[stretch] - rdesktop 1.8.6-2~deb9u1
@@ -702605,11 +702605,11 @@ CVE-2019-11817
 CVE-2019-11816 (Incorrect access control in the WebUI in OPNsense before version 19.1. ...)
 	NOT-FOR-US: OPNsense
 CVE-2019-11814 (An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.1 ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2019-11813 (An issue was discovered in app/View/Elements/Events/View/value_field.c ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2019-11812 (A persistent XSS issue was discovered in app/View/Helper/CommandHelper ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2019-11815 (An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the L ...)
 	{DSA-4465-1 DLA-1824-1}
 	- linux 4.19.37-1 (bug #928989)
@@ -707031,7 +707031,7 @@ CVE-2019-10255 (An Open Redirect vulnerability for all browsers in Jupyter Noteb
 	NOTE: https://blog.jupyter.org/open-redirect-vulnerability-in-jupyter-jupyterhub-adf43583f1e4
 	NOTE: https://github.com/jupyter/notebook/commit/979e0bd15e794ceb00cc63737fcd5fd9addc4a99
 CVE-2019-10254 (In MISP before 2.4.105, the app/View/Layouts/default.ctp default layou ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2019-10253 (A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+  ...)
 	NOT-FOR-US: TeamMate+
 CVE-2019-10252
@@ -710571,7 +710571,7 @@ CVE-2019-9484 (The Glen Dimplex Deutschland GmbH implementation of the Carel pCO
 CVE-2019-9483 (Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows  ...)
 	NOT-FOR-US: Amazon Ring Doorbell
 CVE-2019-9482 (In MISP 2.4.102, an authenticated user can view sightings that they sh ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2019-9481
 	RESERVED
 CVE-2019-9480
@@ -732285,7 +732285,7 @@ CVE-2018-19910
 CVE-2018-19909
 	RESERVED
 CVE-2018-19908 (An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Eve ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2018-1000859
 	REJECTED
 CVE-2018-1000853
@@ -754428,7 +754428,7 @@ CVE-2018-12651 (A Reflected Cross Site Scripting (XSS) Vulnerability was discove
 CVE-2018-12650 (Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting ...)
 	NOT-FOR-US: Adrenalin HRMS
 CVE-2018-12649 (An issue was discovered in app/Controller/UsersController.php in MISP  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2018-12648 (The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Suppo ...)
 	[experimental] - exempi 2.5.0-1
 	- exempi 2.5.0-2 (low; bug #902175)
@@ -757829,7 +757829,7 @@ CVE-2018-11563 (An issue was discovered in Open Ticket Request System (OTRS) 6.0
 	NOTE: https://community.otrs.com/security-advisory-2018-02-security-update-for-otrs-framework/
 	NOTE: https://github.com/OTRS/otrs/commit/50861a2a1183a07daf99cc2e71395e79f022338f
 CVE-2018-11562 (An issue was discovered in MISP 2.4.91. A vulnerability in app/View/El ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2018-11561 (An integer overflow in the unprotected distributeToken function of a s ...)
 	NOT-FOR-US: smart contract implementation for EETHER (EETHER)
 CVE-2018-11560 (The webService binary on Insteon HD IP Camera White 2864-222 devices h ...)
@@ -758733,7 +758733,7 @@ CVE-2018-11247 (The JMX/RMI interface in Nasdaq BWise 5.0 does not require authe
 CVE-2018-11246 (K7TSMngr.exe in K7Computing K7AntiVirus Premium 15.1.0.53 has a Memory ...)
 	NOT-FOR-US: K7Computing K7AntiVirus Premium
 CVE-2018-11245 (app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2018-11244 (The BBE theme before 1.53 for WordPress allows a direct launch of an H ...)
 	NOT-FOR-US: WordPress theme
 CVE-2018-11243 (PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attac ...)
@@ -764786,9 +764786,9 @@ CVE-2018-8951
 CVE-2018-8950
 	RESERVED
 CVE-2018-8949 (An issue was discovered in app/Model/Attribute.php in MISP before 2.4. ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2018-8948 (In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has mul ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2018-8947 (rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encodin ...)
 	NOT-FOR-US: rap2hpoutre Laravel Log Viewer
 CVE-2018-1000141 (I, Librarian version 4.9 and earlier contains an Incorrect Access Cont ...)
@@ -770601,7 +770601,7 @@ CVE-2018-6927 (The futex_requeue function in kernel/futex.c in the Linux kernel
 	[stretch] - linux 4.9.80-1
 	NOTE: Fixed by: https://git.kernel.org/linus/fbe0e839d1e22d88810f3ee3e2f1479be4c0aa4a
 CVE-2018-6926 (In app/Controller/ServersController.php in MISP 2.4.87, a server setti ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2018-6925 (In FreeBSD before 11.2-STABLE(r338986), 11.2-RELEASE-p4, 11.1-RELEASE- ...)
 	- kfreebsd-10 <removed> (unimportant)
 	NOTE: https://security.FreeBSD.org/advisories/FreeBSD-EN-18:11.listen.asc
@@ -791343,7 +791343,7 @@ CVE-2017-16948 (TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause
 CVE-2017-16947
 	RESERVED
 CVE-2017-16946 (The admin_edit function in app/Controller/UsersController.php in MISP  ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2017-16945 (The standardrestorer binary in Arq 5.10 and earlier for Mac allows loc ...)
 	NOT-FOR-US: standardrestorer binary in Arq
 CVE-2017-16942 (In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists  ...)
@@ -792291,7 +792291,7 @@ CVE-2017-16803 (In Libav through 11.11 and 12.x through 12.1, the smacker_decode
 	NOTE: ffmpeg: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/cd4663dc80323ba64989d0c103d51ad3ee0e9c2f
 	NOTE: ffmpeg originally fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commitdiff/b829da363985cb2f80130bba304cc29a632f6446
 CVE-2017-16802 (In the sharingGroupPopulateOrganisations function in app/webroot/js/mi ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2017-16804 (In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function ...)
 	{DSA-4191-1}
 	- redmine 3.4.2-1
@@ -796939,7 +796939,7 @@ CVE-2016-10514 (url_check_format in include/functions.inc.php in Piwigo before 2
 CVE-2016-10513 (Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted ...)
 	- piwigo <removed>
 CVE-2017-15216 (MISP before 2.4.81 has a potential reflected XSS in a quickDelete acti ...)
-	NOT-FOR-US: MISP
+	- misp <itp> (bug #1144317)
 CVE-2017-15215 (Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticate ...)
 	- shaarli <not-affected> (Fixed before initial re-upload to the archive)
 CVE-2017-15214 (Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an  ...)
@@ -799740,7 +799740,7 @@ CVE-2017-14339 (The DNS packet parser in YADIFA before 2.2.6 does not check for
 CVE-2017-14338
 	RESERVED
 CVE-2017-14337 (When MISP before 2.4.80 is configured with X.509 certificate authentic ...)
-	NOT-FOR-US: MISP (Malware Information Sharing Platform and Threat Sharing)
+	- misp <itp> (bug #1144317)
 CVE-2017-14336
 	RESERVED
 CVE-2017-14335 (On Beijing Hanbang Hanbanggaoke devices, because user-controlled input ...)
@@ -801791,7 +801791,7 @@ CVE-2017-13672 (QEMU (aka Quick Emulator), when built with the VGA display emula
 	NOTE: CentOS7 has a backport/upgrade(?) for their frankenstein version
 	NOTE: http://vault.centos.org/7.6.1810/updates/Source/SPackages/qemu-kvm-1.5.3-160.el7_6.3.src.rpm
 CVE-2017-13671 (app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent ...)
-	NOT-FOR-US: MISP (Malware Information Sharing Platform and Threat Sharing)
+	- misp <itp> (bug #1144317)
 CVE-2017-13670 (In BlackCat CMS 1.2, remote authenticated users can upload any file vi ...)
 	NOT-FOR-US: BlackCat CMS
 CVE-2017-13669 (SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswere ...)
@@ -821901,7 +821901,7 @@ CVE-2016-10254 (The allocate_elf function in common.h in elfutils before 0.168 a
 	NOTE: https://blogs.gentoo.org/ago/2016/11/04/elfutils-memory-allocation-failure-in-allocate_elf-common-h/
 	NOTE: https://git.fedorahosted.org/cgit/elfutils.git/commit/?id=191000fdedba3fafe4d5b8cddad3f3318b49c3fb
 CVE-2017-7215 (Cross site scripting in some view elements in the index filter tool in ...)
-	NOT-FOR-US: MISP (Malware Information Sharing Platform and Threat Sharing)
+	- misp <itp> (bug #1144317)
 CVE-2017-7214 (An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x ...)
 	- nova 2:14.0.0-4 (bug #858568)
 	[jessie] - nova <not-affected> (Vulnerable code not present)
@@ -880904,11 +880904,11 @@ CVE-2015-5722 (buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x befo
 	- bind9 1:9.9.5.dfsg-12
 	NOTE: https://kb.isc.org/article/AA-01287
 CVE-2015-5721 (Malware Information Sharing Platform (MISP) before 2.3.90 allows remot ...)
-	NOT-FOR-US: Malware Information Sharing Platform
+	- misp <itp> (bug #1144317)
 CVE-2015-5720 (Multiple cross-site scripting (XSS) vulnerabilities in the template-cr ...)
-	NOT-FOR-US: Malware Information Sharing Platform
+	- misp <itp> (bug #1144317)
 CVE-2015-5719 (app/Controller/TemplatesController.php in Malware Information Sharing  ...)
-	NOT-FOR-US: Malware Information Sharing Platform
+	- misp <itp> (bug #1144317)
 CVE-2015-5718 (Stack-based buffer overflow in the handle_debug_network function in th ...)
 	NOT-FOR-US: Websense Content Gateway
 CVE-2015-5734 (Cross-site scripting (XSS) vulnerability in the legacy theme preview i ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbb044df009a4fe43183803c6a2027dcddffb1f4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbb044df009a4fe43183803c6a2027dcddffb1f4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/4bf4cbde/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list