[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-28370/vitrage

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Mar 1 19:39:10 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cf864ddc by Salvatore Bonaccorso at 2026-03-01T20:38:29+01:00
Update status for CVE-2026-28370/vitrage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -361,8 +361,12 @@ CVE-2026-3037 (An OS command injection vulnerability exists in XWEB Pro version
 CVE-2026-2428 (The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-28370 (In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0 ...)
-	- vitrage <unfixed>
-	TODO: check details
+	- vitrage 15.0.1-1
+	NOTE: Fixed by: https://github.com/openstack/vitrage/commit/5b57e2b32a6d02992a28d9a671ebba5e308fd141 (master)
+	NOTE: Fixed by: https://github.com/openstack/vitrage/commit/89df4bd2ffda1a5ddea66cd828438a6a171a3b11 (15.0.1)
+	NOTE: Fixed by: https://github.com/openstack/vitrage/commit/8f3fc1eb416656d7d68810eff3cfef7fc9672008 (14.0.1)
+	NOTE: Fixed by: https://github.com/openstack/vitrage/commit/2a35b519eb2d50b5ebcd8dd08650b95ef37dfad4 (13.0.1)
+	NOTE: Fixed by: https://github.com/openstack/vitrage/commit/6520c2d9d0ba690ea9f96dc31414c7afd40e9f02 (12.0.1)
 CVE-2026-28364 (In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Mar ...)
 	- ocaml <unfixed> (bug #1129317)
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-01



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf864ddc71958fb561c6eecb4e4a3e05516c2b28

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf864ddc71958fb561c6eecb4e4a3e05516c2b28
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260301/a0ec8b50/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list