[Git][security-tracker-team/security-tracker][master] auto-nfu: Extend vmware rule
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Sep 1 08:49:24 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a556b889 by Moritz Muehlenhoff at 2026-09-01T09:49:12+02:00
auto-nfu: Extend vmware rule
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -4170,7 +4170,7 @@ CVE-2026-59274 (The UnZipTransformer does not limit decompressed entry size or e
CVE-2026-59271 (When the RabbitMQ management aliveness check fails, the configured adm ...)
NOT-FOR-US: VMware
CVE-2026-59270 (Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-58070 (A vulnerability that records guest OS processing credentials in cleart ...)
NOT-FOR-US: Veeam
CVE-2026-56547 (The Apple profile generated for the Apple built-in Mail, Calendar and ...)
@@ -4222,7 +4222,7 @@ CVE-2026-47879 (Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbit
CVE-2026-47878 (DefaultExecutionContextSerializer, used by default in Spring Batch's J ...)
TODO: check
CVE-2026-47877 (Spring Security Authorization Server's default consent page renders us ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47875 (Applications that deserialize execution contexts with Jackson2Executio ...)
TODO: check
CVE-2026-47874 (The vulnerability occurs when a client sends HTTP/1.1 pipelined reques ...)
@@ -4260,9 +4260,9 @@ CVE-2026-47844 (In specific scenarios, the Reactor Netty HTTP Server may leak ex
CVE-2026-47843 (In specific scenarios involving multiple clients with different DNS re ...)
NOT-FOR-US: VMware
CVE-2026-47842 (Applications using AesBytesEncryptor with the two-argument constructor ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47834 (Spring Data JPA's Sort validation can be bypassed when parameters cont ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-47666 (Penpot is an open-source design and prototyping platform. In versions ...)
NOT-FOR-US: Penpot
CVE-2026-47665 (Penpot is an open-source design and prototyping platform. In versions ...)
@@ -6464,7 +6464,7 @@ CVE-2026-43670 (A Content Security Policy bypass was addressed with improved enf
CVE-2026-43657 (A permissions issue was addressed with additional restrictions. This i ...)
NOT-FOR-US: Apple
CVE-2026-41707 (Authentication Bypass by Capture-replay vulnerability in Spring Spring ...)
- TODO: check
+ NOT-FOR-US: VMware
CVE-2026-3002 (The Gutenverse \u2013 Ultimate WordPress FSE Blocks Addons & Ecosystem ...)
NOT-FOR-US: WordPress plugin
CVE-2026-39113 (Buffer Overflow vulnerability in SQLite affected version source snapsh ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -843,6 +843,7 @@
- product: Spring Cloud Sleuth
- product: Spring Cloud Stream
- product: Spring Data Commons
+ - product: Spring Data JPA
- product: Spring Data KeyValue
- product: Spring Data MongoDB
- product: Spring Data REST
@@ -852,6 +853,7 @@
- product: Spring LDAP
- product: Spring REST Docs
- product: Spring Retry
+ - product: Spring Security
- product: Spring Statemachine
- product: Spring Tools for Eclipse
- product: Spring Web Flow
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a556b889eb0cdd79bf2bb03f3facebd1d535c2cf
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a556b889eb0cdd79bf2bb03f3facebd1d535c2cf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/035cecbb/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list