[Git][security-tracker-team/security-tracker][master] auto-nfu: Extend vmware rule
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 31 17:25:08 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5d486be4 by Moritz Muehlenhoff at 2026-08-31T18:24:45+02:00
auto-nfu: Extend vmware rule
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -2288,7 +2288,7 @@ CVE-2026-59319 (RedisChatMemoryRepository.findByMetadata() builds RediSearch tag
CVE-2026-59317 (DeadLetterPublishingRecovererFactory reads the retry_topic-original-ti ...)
NOT-FOR-US: VMware
CVE-2026-59316 (Spring Authorization Server's default consent page renders user-contro ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59315 (The Spring Cloud Config Monitor is susceptible to Denial of Service at ...)
NOT-FOR-US: VMware
CVE-2026-59314 (Applications that build a Content-Disposition header value from untrus ...)
@@ -2300,15 +2300,15 @@ CVE-2026-59311 (A local unprivileged user on the same host can redirect all Zip/
CVE-2026-59307 (An operator who calls JdbcMessageStore.addAllowedPatterns(...) to rest ...)
NOT-FOR-US: VMware
CVE-2026-59306 (Potential for deserialization of untrusted types in Spring Cloud Strea ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59305 (Partition interceptor may be improperly added while sending message. S ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59304 (Improper caching of the original content type in Spring Cloud Stream A ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59303 (Dynamic destination cache size is not properly bound in Spring Cloud S ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59302 (Potential for logging sensitive data in Spring Cloud Stream. Spring Cl ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59301 (Potential for logging sensitive data in Spring Cloud Function Azure. S ...)
NOT-FOR-US: VMware
CVE-2026-59300 (Potential for logging sensitive data in Spring Cloud Function AWS. Spr ...)
@@ -2338,7 +2338,7 @@ CVE-2026-59286 (The GraphiQL page bundled with Spring for GraphQL loads JavaScri
CVE-2026-59285 (Spring for GraphQL applications are vulnerable to Unsafe Deserializati ...)
NOT-FOR-US: VMware
CVE-2026-59284 (There is no allow list for property keys when Spring Cloud Commons wri ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59283 (Applications that evaluate Spring Expression Language (SpEL) expressio ...)
TODO: check
CVE-2026-59282 (Spring Framework applications that use Spring's data binding infrastru ...)
@@ -2874,7 +2874,7 @@ CVE-2026-5680 (A flaw was found in Undertow. A remote attacker could exploit thi
CVE-2026-5218 (Improper neutralization of Script-Related HTML tags in a web page (bas ...)
NOT-FOR-US: E-Commerce Pack
CVE-2026-59355 (In versions of Spring Authorization Server 1.5.0 through 1.5.7, the au ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59354 (In versions of Spring Security's OAuth2 Authorization Server module 7. ...)
TODO: check
CVE-2026-59280 (Applications using Spring Framework's FreeMarker integration may be vu ...)
@@ -51473,7 +51473,7 @@ CVE-2026-33434 (Wazuh is a free and open source platform used for threat prevent
CVE-2026-2594 (The Smart Custom Fields plugin for WordPress is vulnerable to Stored C ...)
NOT-FOR-US: WordPress plugin
CVE-2026-22752 (Authentication bypass by primary weakness vulnerability in Spring Secu ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-21770 (HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hija ...)
NOT-FOR-US: HCL
CVE-2026-15997 (Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -833,12 +833,15 @@
- product: Reactor Netty
- product: Spring AI
- product: Spring AMQP
+ - product: Spring Authorization Server
- product: Spring Boot
+ - product: Spring Cloud Commons
- product: Spring Cloud Config
- product: Spring Cloud Function
- product: Spring Cloud Gateway
- product: Spring Cloud Gateway Server Webflux
- product: Spring Cloud Sleuth
+ - product: Spring Cloud Stream
- product: Spring Data Commons
- product: Spring Data KeyValue
- product: Spring Data MongoDB
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d486be4f78fd299ba0052111bf779de6bf4e537
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d486be4f78fd299ba0052111bf779de6bf4e537
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/b9cf697b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list