[Git][security-tracker-team/security-tracker][master] 2 commits: auto-nfu: Add two more products for the VMware CNA rule

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 31 19:28:54 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7eaf748f by Salvatore Bonaccorso at 2026-07-31T20:26:32+02:00
auto-nfu: Add two more products for the VMware CNA rule

- - - - -
ebf9d319 by Salvatore Bonaccorso at 2026-07-31T20:26:35+02:00
Process some NFUs

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -810,11 +810,11 @@ CVE-2026-5057 (ATEN Unizon RpcProvider Missing Authentication Denial-of-Service
 CVE-2026-59952 (Valibot helps validate data using a schema. Versions prior to 1.4.2 ca ...)
 	NOT-FOR-US: Valibot
 CVE-2026-59328 (Spring Tools for Eclipse renders Spring Boot starter wizard dependency ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59327 (Spring Tools for Eclipse stores the Spring Boot DevTools remote secret ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-59326 (The Spring Boot language server logs the raw value of the https_proxy/ ...)
-	TODO: check
+	NOT-FOR-US: WMware
 CVE-2026-58066 (Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3 ...)
 	NOT-FOR-US: Rocket.Chat
 CVE-2026-58046 (Improper neutralization in the Plesk XML-RPC API allows a remote authe ...)
@@ -842,11 +842,11 @@ CVE-2026-48449 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authori
 CVE-2026-48448 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
 	NOT-FOR-US: Adobe
 CVE-2026-47882 (When enabling Spring Boot DevTools support for a remote application ta ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-47873 (The Boot Dashboard Docker integration in Spring Tools publishes contai ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-47858 (Starting Spring Boot applications in the Spring Tools with the live in ...)
-	TODO: check
+	NOT-FOR-US: WMware
 CVE-2026-46678 (Pydantic AI is a Python agent framework for building Generative AI app ...)
 	NOT-FOR-US: Pydantic AI
 CVE-2026-3093 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
@@ -72859,9 +72859,9 @@ CVE-2026-40979 (In Spring AI, having access to a shared environment can expose t
 CVE-2026-40978 (SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allow ...)
 	NOT-FOR-US: VMware
 CVE-2026-40969 (The raw message of every server-side AuthenticationException is return ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-40968 (When an authenticated user is denied access to a gRPC method, their au ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-40966 (In Spring AI, an attacker can bypass conversation isolation and exfilt ...)
 	NOT-FOR-US: VMware
 CVE-2026-40556


=====================================
data/packages/nfu.yaml
=====================================
@@ -781,19 +781,21 @@
       - product: Spring Data Commons
       - product: Spring Data KeyValue
       - product: Spring Data MongoDB
-      - product: Spring Data Relational
       - product: Spring Data REST
-      - product: Spring for Apache Kafka
-      - product: Spring for Apache Pulsar
-      - product: Spring for GraphQL
+      - product: Spring Data Relational
       - product: Spring HATEOAS
       - product: Spring Integration
       - product: Spring LDAP
       - product: Spring REST Docs
       - product: Spring Retry
       - product: Spring Statemachine
+      - product: Spring Tools for Eclipse
       - product: Spring Web Flow
       - product: Spring Web Services
+      - product: Spring for Apache Kafka
+      - product: Spring for Apache Pulsar
+      - product: Spring for GraphQL
+      - product: Spring gRPC
       - product: VMware Cloud Foundation
       - product: VMware ESXi
       - product: VMware NSX



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5bde46ed9ee1230a95c37400bd708388ee81beac...ebf9d319c45f74583e1809e452e7fa1c5770b088

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5bde46ed9ee1230a95c37400bd708388ee81beac...ebf9d319c45f74583e1809e452e7fa1c5770b088
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/fcb7b5f3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list