[Git][security-tracker-team/security-tracker][master] auto-nfu: Extend mediawiki rule

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Jul 1 22:38:24 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
942a24ff by Moritz Muehlenhoff at 2026-07-01T23:37:58+02:00
auto-nfu: Extend mediawiki rule

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-8857 (A vulnerability in Wikimedia Foundation timeline.   This vulnerability ...)
-	TODO: check
+	NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-8480 (A vulnerability was discovered on Stormshield Network Security 4.3.0 t ...)
 	NOT-FOR-US: Stormshield
 CVE-2026-8387 (A vulnerability in allegroai/clearml versions up to and including 1.16 ...)
@@ -55,7 +55,7 @@ CVE-2026-58127 (PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service o
 CVE-2026-58126 (PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execu ...)
 	NOT-FOR-US: PACSgear PACS Scan
 CVE-2026-58038 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
-	TODO: check
+	NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-58035 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
 	TODO: check
 CVE-2026-58034 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
@@ -278,9 +278,9 @@ CVE-2026-13760 (OS command injection in the NodejsFunction Docker bundling pipel
 CVE-2026-13733 (The Download Manager plugin for WordPress is vulnerable to Stored Cros ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-13707 (Session fixation vulnerability in Wikimedia Foundation OAuth.   This v ...)
-	TODO: check
+	NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-13706 (Improper input validation vulnerability in Wikimedia Foundation UrlSho ...)
-	TODO: check
+	NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-13603 (The payment integration pretix-oppwa provides support  for the payment ...)
 	NOT-FOR-US: rami.io products
 CVE-2026-13602 (We found a chain of combining multiple weaknesses in the product that  ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -860,6 +860,9 @@
       - product: Mediawiki - WikiLove Extension
       - product: Mediawiki - Wikilove Extension
       - product: Mediawiki - Wikistories
+      - product: OAuth
+      - product: timeline
+      - product: UrlShortener
 # Description based rules
 - reason: Advantech
   description: '.*\bAdvantech\b.*'



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/942a24ff9c5776ddb2b36b9d6fd4dcc265780ae1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/942a24ff9c5776ddb2b36b9d6fd4dcc265780ae1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260701/eb84f665/attachment.htm>


More information about the debian-security-tracker-commits mailing list