[Git][security-tracker-team/security-tracker][master] 2 commits: auto-nfu: Add two more products for the VMware CNA rule
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 31 19:28:54 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7eaf748f by Salvatore Bonaccorso at 2026-07-31T20:26:32+02:00
auto-nfu: Add two more products for the VMware CNA rule
- - - - -
ebf9d319 by Salvatore Bonaccorso at 2026-07-31T20:26:35+02:00
Process some NFUs
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -810,11 +810,11 @@ CVE-2026-5057 (ATEN Unizon RpcProvider Missing Authentication Denial-of-Service
CVE-2026-59952 (Valibot helps validate data using a schema. Versions prior to 1.4.2 ca ...)
NOT-FOR-US: Valibot
CVE-2026-59328 (Spring Tools for Eclipse renders Spring Boot starter wizard dependency ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59327 (Spring Tools for Eclipse stores the Spring Boot DevTools remote secret ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-59326 (The Spring Boot language server logs the raw value of the https_proxy/ ...)
- TODO: check
+ NOT-FOR-US: WMware
CVE-2026-58066 (Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3 ...)
NOT-FOR-US: Rocket.Chat
CVE-2026-58046 (Improper neutralization in the Plesk XML-RPC API allows a remote authe ...)
@@ -842,11 +842,11 @@ CVE-2026-48449 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authori
CVE-2026-48448 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
NOT-FOR-US: Adobe
CVE-2026-47882 (When enabling Spring Boot DevTools support for a remote application ta ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47873 (The Boot Dashboard Docker integration in Spring Tools publishes contai ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47858 (Starting Spring Boot applications in the Spring Tools with the live in ...)
- TODO: check
+ NOT-FOR-US: WMware
CVE-2026-46678 (Pydantic AI is a Python agent framework for building Generative AI app ...)
NOT-FOR-US: Pydantic AI
CVE-2026-3093 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
@@ -72859,9 +72859,9 @@ CVE-2026-40979 (In Spring AI, having access to a shared environment can expose t
CVE-2026-40978 (SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allow ...)
NOT-FOR-US: VMware
CVE-2026-40969 (The raw message of every server-side AuthenticationException is return ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-40968 (When an authenticated user is denied access to a gRPC method, their au ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-40966 (In Spring AI, an attacker can bypass conversation isolation and exfilt ...)
NOT-FOR-US: VMware
CVE-2026-40556
=====================================
data/packages/nfu.yaml
=====================================
@@ -781,19 +781,21 @@
- product: Spring Data Commons
- product: Spring Data KeyValue
- product: Spring Data MongoDB
- - product: Spring Data Relational
- product: Spring Data REST
- - product: Spring for Apache Kafka
- - product: Spring for Apache Pulsar
- - product: Spring for GraphQL
+ - product: Spring Data Relational
- product: Spring HATEOAS
- product: Spring Integration
- product: Spring LDAP
- product: Spring REST Docs
- product: Spring Retry
- product: Spring Statemachine
+ - product: Spring Tools for Eclipse
- product: Spring Web Flow
- product: Spring Web Services
+ - product: Spring for Apache Kafka
+ - product: Spring for Apache Pulsar
+ - product: Spring for GraphQL
+ - product: Spring gRPC
- product: VMware Cloud Foundation
- product: VMware ESXi
- product: VMware NSX
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5bde46ed9ee1230a95c37400bd708388ee81beac...ebf9d319c45f74583e1809e452e7fa1c5770b088
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5bde46ed9ee1230a95c37400bd708388ee81beac...ebf9d319c45f74583e1809e452e7fa1c5770b088
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/fcb7b5f3/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list