[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Feb 12 05:01:53 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3e0a9525 by Salvatore Bonaccorso at 2026-02-12T06:01:37+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -107,9 +107,9 @@ CVE-2025-8668 (Improper Neutralization of Input During Web Page Generation (XSS
 CVE-2025-8025 (Missing Authentication for Critical Function, Improper Access Control  ...)
 	NOT-FOR-US: Dinosoft ERP
 CVE-2025-70297 (A stored cross-site scripting (XSS) vulnerability in the recipe asset  ...)
-	TODO: check
+	NOT-FOR-US: Mealie
 CVE-2025-70296 (A stored HTML injection vulnerability in the Recipe Notes rendering co ...)
-	TODO: check
+	NOT-FOR-US: Mealie
 CVE-2025-70085 (An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer ha ...)
 	NOT-FOR-US: OpenSatKit
 CVE-2025-70084 (Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers ...)
@@ -119,7 +119,7 @@ CVE-2025-70083 (An issue was discovered in OpenSatKit 2.2.1. The DirName field i
 CVE-2025-70029 (An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to ob ...)
 	NOT-FOR-US: Sunbird-Ed SunbirdEd-portal
 CVE-2025-69874 (nanotar through 0.2.0 has a path traversal vulnerability in parseTar() ...)
-	TODO: check
+	NOT-FOR-US: nanotar Node.js module
 CVE-2025-69873 (ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerab ...)
 	TODO: check
 CVE-2025-69872 (DiskCache (python-diskcache) through 5.6.3 uses Python pickle for seri ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e0a9525a54627429998161356c5196d9937bfe5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e0a9525a54627429998161356c5196d9937bfe5
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260212/5cc76036/attachment.htm>


More information about the debian-security-tracker-commits mailing list