[Git][security-tracker-team/security-tracker][master] auto-nfu: Extend Apache rule
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Jun 1 22:19:18 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bf722a76 by Moritz Muehlenhoff at 2026-06-01T23:18:57+02:00
auto-nfu: Extend Apache rule
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -25,7 +25,7 @@ CVE-2026-7858 (A Deserialization of Untrusted Data vulnerability affecting Teamw
CVE-2026-7770 (IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solut ...)
NOT-FOR-US: IBM
CVE-2026-49361 (Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBa ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-49270 (Exposure of Sensitive Information Through Metadata vulnerability in Ap ...)
TODO: check
CVE-2026-49157 (Incorrect Default Permissions vulnerability in Apache ActiveMQ. This ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -337,6 +337,7 @@
- product: Apache Doris-MCP-Server
- product: Apache Flink
- product: Apache Fineract
+ - product: Apache Fluss (incubating)
- product: Apache Fory
- product: Apache Geode
- product: Apache HertzBeat
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf722a767bb47ba05e8c3f8f264cce1359a202c4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf722a767bb47ba05e8c3f8f264cce1359a202c4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260601/38084f70/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list