[Git][security-tracker-team/security-tracker][master] auto-nfu: Extend vmware rule

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 1 08:49:24 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a556b889 by Moritz Muehlenhoff at 2026-09-01T09:49:12+02:00
auto-nfu: Extend vmware rule

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -4170,7 +4170,7 @@ CVE-2026-59274 (The UnZipTransformer does not limit decompressed entry size or e
 CVE-2026-59271 (When the RabbitMQ management aliveness check fails, the configured adm ...)
 	NOT-FOR-US: VMware
 CVE-2026-59270 (Spring Security's embedded UnboundID LDAP server (UnboundIdContainer)  ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-58070 (A vulnerability that records guest OS processing credentials in cleart ...)
 	NOT-FOR-US: Veeam
 CVE-2026-56547 (The Apple profile generated for the Apple built-in Mail, Calendar and  ...)
@@ -4222,7 +4222,7 @@ CVE-2026-47879 (Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbit
 CVE-2026-47878 (DefaultExecutionContextSerializer, used by default in Spring Batch's J ...)
 	TODO: check
 CVE-2026-47877 (Spring Security Authorization Server's default consent page renders us ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-47875 (Applications that deserialize execution contexts with Jackson2Executio ...)
 	TODO: check
 CVE-2026-47874 (The vulnerability occurs when a client sends HTTP/1.1 pipelined reques ...)
@@ -4260,9 +4260,9 @@ CVE-2026-47844 (In specific scenarios, the Reactor Netty HTTP Server may leak ex
 CVE-2026-47843 (In specific scenarios involving multiple clients with different DNS re ...)
 	NOT-FOR-US: VMware
 CVE-2026-47842 (Applications using AesBytesEncryptor with the two-argument constructor ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-47834 (Spring Data JPA's Sort validation can be bypassed when parameters cont ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-47666 (Penpot is an open-source design and prototyping platform. In versions  ...)
 	NOT-FOR-US: Penpot
 CVE-2026-47665 (Penpot is an open-source design and prototyping platform. In versions  ...)
@@ -6464,7 +6464,7 @@ CVE-2026-43670 (A Content Security Policy bypass was addressed with improved enf
 CVE-2026-43657 (A permissions issue was addressed with additional restrictions. This i ...)
 	NOT-FOR-US: Apple
 CVE-2026-41707 (Authentication Bypass by Capture-replay vulnerability in Spring Spring ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-3002 (The Gutenverse \u2013 Ultimate WordPress FSE Blocks Addons & Ecosystem ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-39113 (Buffer Overflow vulnerability in SQLite affected version source snapsh ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -843,6 +843,7 @@
       - product: Spring Cloud Sleuth
       - product: Spring Cloud Stream
       - product: Spring Data Commons
+      - product: Spring Data JPA
       - product: Spring Data KeyValue
       - product: Spring Data MongoDB
       - product: Spring Data REST
@@ -852,6 +853,7 @@
       - product: Spring LDAP
       - product: Spring REST Docs
       - product: Spring Retry
+      - product: Spring Security
       - product: Spring Statemachine
       - product: Spring Tools for Eclipse
       - product: Spring Web Flow



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a556b889eb0cdd79bf2bb03f3facebd1d535c2cf

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a556b889eb0cdd79bf2bb03f3facebd1d535c2cf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/035cecbb/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list