[Git][security-tracker-team/security-tracker][master] auto-nfu: Extend vmware rule

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 31 17:25:08 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5d486be4 by Moritz Muehlenhoff at 2026-08-31T18:24:45+02:00
auto-nfu: Extend vmware rule

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -2288,7 +2288,7 @@ CVE-2026-59319 (RedisChatMemoryRepository.findByMetadata() builds RediSearch tag
 CVE-2026-59317 (DeadLetterPublishingRecovererFactory reads the retry_topic-original-ti ...)
 	NOT-FOR-US: VMware
 CVE-2026-59316 (Spring Authorization Server's default consent page renders user-contro ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59315 (The Spring Cloud Config Monitor is susceptible to Denial of Service at ...)
 	NOT-FOR-US: VMware
 CVE-2026-59314 (Applications that build a Content-Disposition header value from untrus ...)
@@ -2300,15 +2300,15 @@ CVE-2026-59311 (A local unprivileged user on the same host can redirect all Zip/
 CVE-2026-59307 (An operator who calls JdbcMessageStore.addAllowedPatterns(...) to rest ...)
 	NOT-FOR-US: VMware
 CVE-2026-59306 (Potential for deserialization of untrusted types in Spring Cloud Strea ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59305 (Partition interceptor may be improperly added while sending message. S ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59304 (Improper caching of the original content type in Spring Cloud Stream A ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59303 (Dynamic destination cache size is not properly bound in Spring Cloud S ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59302 (Potential for logging sensitive data in Spring Cloud Stream. Spring Cl ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59301 (Potential for logging sensitive data in Spring Cloud Function Azure. S ...)
 	NOT-FOR-US: VMware
 CVE-2026-59300 (Potential for logging sensitive data in Spring Cloud Function AWS. Spr ...)
@@ -2338,7 +2338,7 @@ CVE-2026-59286 (The GraphiQL page bundled with Spring for GraphQL loads JavaScri
 CVE-2026-59285 (Spring for GraphQL applications are vulnerable to Unsafe Deserializati ...)
 	NOT-FOR-US: VMware
 CVE-2026-59284 (There is no allow list for property keys when Spring Cloud Commons wri ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59283 (Applications that evaluate Spring Expression Language (SpEL) expressio ...)
 	TODO: check
 CVE-2026-59282 (Spring Framework applications that use Spring's data binding infrastru ...)
@@ -2874,7 +2874,7 @@ CVE-2026-5680 (A flaw was found in Undertow. A remote attacker could exploit thi
 CVE-2026-5218 (Improper neutralization of Script-Related HTML tags in a web page (bas ...)
 	NOT-FOR-US: E-Commerce Pack
 CVE-2026-59355 (In versions of Spring Authorization Server 1.5.0 through 1.5.7, the au ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59354 (In versions of Spring Security's OAuth2 Authorization Server module 7. ...)
 	TODO: check
 CVE-2026-59280 (Applications using Spring Framework's FreeMarker integration may be vu ...)
@@ -51473,7 +51473,7 @@ CVE-2026-33434 (Wazuh is a free and open source platform used for threat prevent
 CVE-2026-2594 (The Smart Custom Fields plugin for WordPress is vulnerable to Stored C ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-22752 (Authentication bypass by primary weakness vulnerability in Spring Secu ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-21770 (HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hija ...)
 	NOT-FOR-US: HCL
 CVE-2026-15997 (Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc.  ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -833,12 +833,15 @@
       - product: Reactor Netty
       - product: Spring AI
       - product: Spring AMQP
+      - product: Spring Authorization Server
       - product: Spring Boot
+      - product: Spring Cloud Commons
       - product: Spring Cloud Config
       - product: Spring Cloud Function
       - product: Spring Cloud Gateway
       - product: Spring Cloud Gateway Server Webflux
       - product: Spring Cloud Sleuth
+      - product: Spring Cloud Stream
       - product: Spring Data Commons
       - product: Spring Data KeyValue
       - product: Spring Data MongoDB



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d486be4f78fd299ba0052111bf779de6bf4e537

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d486be4f78fd299ba0052111bf779de6bf4e537
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/b9cf697b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list