[Git][security-tracker-team/security-tracker][master] CVE-2025-27404,CVE-2025-27405,CVE-2025-27609,CVE-2025-30164/icingaweb2: bookworm postponed
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Mon Jul 13 21:21:45 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4464aa4f by Sylvain Beucler at 2026-07-13T22:21:39+02:00
CVE-2025-27404,CVE-2025-27405,CVE-2025-27609,CVE-2025-30164/icingaweb2: bookworm postponed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -206184,6 +206184,7 @@ CVE-2025-30217 (Frappe is a full-stack web application framework. Prior to versi
NOT-FOR-US: Frappe Framework
CVE-2025-30164 (Icinga Web 2 is an open source monitoring web interface, framework and ...)
- icingaweb2 2.12.4-1
+ [bookworm] - icingaweb2 <postponed> (Minor issue, open redirect, unknown patch)
[bullseye] - icingaweb2 <postponed> (Minor issue, open redirect, unknown patch)
NOTE: https://github.com/Icinga/icingaweb2/security/advisories/GHSA-8r73-6686-wv8q
CVE-2025-30073 (An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0. Th ...)
@@ -206272,6 +206273,7 @@ CVE-2025-28361 (Unauthorized stack overflow vulnerability in Telesquare TLR-2005
NOT-FOR-US: Telesquare TLR-2005KSH
CVE-2025-27609 (Icinga Web 2 is an open source monitoring web interface, framework and ...)
- icingaweb2 2.12.4-1
+ [bookworm] - icingaweb2 <postponed> (Minor issue, reflected XSS, unknown patch)
[bullseye] - icingaweb2 <postponed> (Minor issue, reflected XSS, unknown patch)
NOTE: https://github.com/Icinga/icingaweb2/security/advisories/GHSA-5cjw-fwjc-8j38
CVE-2025-27406 (Icinga Reporting is the central component for reporting related functi ...)
@@ -206280,10 +206282,12 @@ CVE-2025-27406 (Icinga Reporting is the central component for reporting related
NOTE: https://github.com/Icinga/icingaweb2-module-reporting/security/advisories/GHSA-7qvq-54vm-r7hx
CVE-2025-27405 (Icinga Web 2 is an open source monitoring web interface, framework and ...)
- icingaweb2 2.12.4-1
+ [bookworm] - icingaweb2 <postponed> (Minor issue, reflected XSS, unknown patch)
[bullseye] - icingaweb2 <postponed> (Minor issue, reflected XSS, unknown patch)
NOTE: https://github.com/Icinga/icingaweb2/security/advisories/GHSA-3x37-fjc3-ch8w
CVE-2025-27404 (Icinga Web 2 is an open source monitoring web interface, framework and ...)
- icingaweb2 2.12.4-1
+ [bookworm] - icingaweb2 <postponed> (Minor issue, reflected XSS, unknown patch)
[bullseye] - icingaweb2 <postponed> (Minor issue, reflected XSS, unknown patch)
NOTE: https://github.com/Icinga/icingaweb2/security/advisories/GHSA-c6pg-h955-wf66
CVE-2025-27267 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4464aa4f1b90cc262acb86ccbc1c7d65b8582c57
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4464aa4f1b90cc262acb86ccbc1c7d65b8582c57
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260713/dba6cb70/attachment.htm>
More information about the debian-security-tracker-commits
mailing list