[Git][security-tracker-team/security-tracker][master] Track fixed version for zabbix issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 20 13:34:19 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
45f34f99 by Salvatore Bonaccorso at 2026-08-20T13:56:04+02:00
Track fixed version for zabbix issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -93124,20 +93124,20 @@ CVE-2026-29090 (### Summary  A SQL injection vulnerability exists in Rucio versi
 CVE-2026-29080 (A SQL injection vulnerability in `FilterEngine.create_sqla_query()` al ...)
 	NOT-FOR-US: Rucio
 CVE-2026-23928 (The Item history widget (in Zabbix 7.0+) or the Plain text widget (in  ...)
-	- zabbix <unfixed> (bug #1137209)
+	- zabbix 1:7.0.27+dfsg-1 (bug #1137209)
 	[trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
 	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
 	NOTE: https://support.zabbix.com/browse/ZBX-27760
 	NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/1522d3a2116ad1e10a05ac08bb5f7cd080d1204d (master)
 	NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/59f436f726cde91c5c5974f7da0cab41e0b8659a (7.0.24rc1)
 CVE-2026-23927 (A user able to connect to Agent 2 can inject an Oracle TNS connection  ...)
-	- zabbix <unfixed> (bug #1137209)
+	- zabbix 1:7.0.27+dfsg-1 (bug #1137209)
 	[trixie] - zabbix <no-dsa> (Minor issue)
 	[bookworm] - zabbix <no-dsa> (Minor issue)
 	NOTE: https://support.zabbix.com/browse/ZBX-27759
 	NOTE: Fixed by: https://github.com/zabbix/zabbix/commit/6c56fc7f360c79688c67cd599787d6b4db2b172d (master)
 CVE-2026-23926 (An authenticated (non-super) administrator can create a maintenance pe ...)
-	- zabbix <unfixed> (bug #1137209)
+	- zabbix 1:7.0.27+dfsg-1 (bug #1137209)
 	[trixie] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
 	[bookworm] - zabbix <ignored> (The WEB UI is only supported for access by trusted users, no security updates issued for it, #1124558)
 	NOTE: https://support.zabbix.com/browse/ZBX-27758
@@ -118625,7 +118625,7 @@ CVE-2026-27651 (When the ngx_mail_auth_http_modulemodule is enabled on NGINX Plu
 CVE-2026-26809
 	REJECTED
 CVE-2026-23924 (Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.co ...)
-	- zabbix <unfixed> (bug #1132226)
+	- zabbix 1:7.0.27+dfsg-1 (bug #1132226)
 	[trixie] - zabbix <no-dsa> (Minor issue)
 	[bookworm] - zabbix <no-dsa> (Minor issue)
 	NOTE: https://support.zabbix.com/browse/ZBX-27642



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45f34f994c1e8c219928518d1871641a0f6492c2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45f34f994c1e8c219928518d1871641a0f6492c2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/e61e7ddf/attachment.htm>


More information about the debian-security-tracker-commits mailing list