[Git][security-tracker-team/security-tracker][master] auto-nfu: Update vmware rule

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Jun 9 08:05:01 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
82277f94 by Moritz Muehlenhoff at 2026-06-09T09:04:53+02:00
auto-nfu: Update vmware rule

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -22247,13 +22247,13 @@ CVE-2026-41142 (OpenEXR provides the specification and reference implementation
 CVE-2026-41139 (Math.js is an extensive math library for JavaScript and Node.js. From  ...)
 	NOT-FOR-US: Math.js
 CVE-2026-41004 (When enabling trace logging in Spring Cloud Config Server sensitive in ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-41002 (The base directory (`spring.cloud.config.server.git.basedir`) used by  ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-40982 (Spring Cloud Config allows applications to serve arbitrary text and bi ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-40981 (When using Google Secrets Manager as a backend for the Spring Cloud Co ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-40332 (Masa CMS is affected by an Open Redirect vulnerability due to improper ...)
 	NOT-FOR-US: Masa CMS
 CVE-2026-40326 (Masa CMS is a content management system forked from Mura CMS. In versi ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -675,6 +675,7 @@
       - product: Cloud Foundry
       - product: Spring AI
       - product: Spring Boot
+      - product: Spring Cloud Config
       - product: Spring Cloud Function
       - product: Spring Cloud Gateway
       - product: Spring Cloud Gateway Server Webflux



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82277f9458eab6e9d88a50f45bf6169906a5dc89

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/82277f9458eab6e9d88a50f45bf6169906a5dc89
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260609/2b3e1fd2/attachment.htm>


More information about the debian-security-tracker-commits mailing list