[Git][security-tracker-team/security-tracker][master] Add three new issues in hiawatha, itp'ed
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jan 26 20:54:34 GMT 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5bd9cd67 by Salvatore Bonaccorso at 2026-01-26T21:54:14+01:00
Add three new issues in hiawatha, itp'ed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -95,11 +95,11 @@ CVE-2025-59091 (Multiple hardcoded credentials have been identified, which are a
CVE-2025-59090 (On the exos 9300 server, a SOAP API is reachable on port 8002. This AP ...)
NOT-FOR-US: dormakaba
CVE-2025-57785 (A Double Free in XSLT `show_index` has been identified in Hiawatha web ...)
- TODO: check
+ - hiawatha <itp> (bug #1094318)
CVE-2025-57784 (Tomahawk auth timing attack due to usage of `strcmp` has been identifi ...)
- TODO: check
+ - hiawatha <itp> (bug #1094318)
CVE-2025-57783 (Improper header parsing may lead to request smuggling has been identif ...)
- TODO: check
+ - hiawatha <itp> (bug #1094318)
CVE-2025-50537 (Stack overflow vulnerability in eslint before 9.26.0 when serializing ...)
TODO: check
CVE-2025-41083 (Vulnerability in Altitude Authentication Service and Altitude Communic ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5bd9cd673bca4eb5452eb8522fef6dafe6ac2413
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5bd9cd673bca4eb5452eb8522fef6dafe6ac2413
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260126/3a24f874/attachment.htm>
More information about the debian-security-tracker-commits
mailing list