[Git][security-tracker-team/security-tracker][master] auto-nfu: Track the entire Grafana CNA as NFU
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 3 13:15:43 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d63cfd15 by Moritz Muehlenhoff at 2026-09-03T12:15:52+02:00
auto-nfu: Track the entire Grafana CNA as NFU
While src:grafana was packaged briefly, it has been removed eight years
ago and given the quick upstream pace and the complexities of the web UI
it will unlikely come back.
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -470,7 +470,7 @@ CVE-2026-20212 (A vulnerability in the Silicon One integration for Cisco Nexus 9
CVE-2026-19698 (The GutenKit WordPress plugin before 2.5.1 does not validate or escape ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19475 (An authenticated user with permission to query a SQL data source can b ...)
- TODO: check
+ NOT-FOR-US: Grafana
CVE-2026-19219 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.3.812, insuffic ...)
NOT-FOR-US: Progress Software
CVE-2026-19117 (Under specific conditions, an attacker can register an attacker-contro ...)
@@ -494,7 +494,7 @@ CVE-2026-14326 (The Timetics WordPress plugin through 1.0.61 does not enforce pe
CVE-2026-14255 (A maliciously crafted IFC file, when parsed through certain Autodesk p ...)
NOT-FOR-US: Autodesk
CVE-2026-14199 (Only self-managed Grafana instances with Auth Proxy authentication and ...)
- TODO: check
+ NOT-FOR-US: Grafana
CVE-2026-12704 (When SAML IdP-initiated login is enabled in Grafana Enterprise, the SA ...)
NOT-FOR-US: Grafana Labs
CVE-2026-10821 (The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize ...)
@@ -6991,7 +6991,7 @@ CVE-2026-19401 (Any remote client can crash a (debugging/non-release build type)
CVE-2026-19271 (Improper Neutralization of Special Elements used in an LDAP Query ('LD ...)
NOT-FOR-US: Liderahenk
CVE-2026-19197 (A user with organization administrator permissions can delete dashboar ...)
- TODO: check
+ NOT-FOR-US: Grafana
CVE-2026-19042 (A command injection vulnerability in TeamViewer Full Client and Host f ...)
NOT-FOR-US: TeamViewer
CVE-2026-18916 (Any remote client can crash a NSD serve child, by throttling the TCP r ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -125,6 +125,8 @@
cna: GitHub_P
- reason: Google devices
cna: Google_Devices
+- reason: Grafana
+ cna: GRAFANA
- reason: Hanwha Vision
cna: Hanwha_Vision
- reason: HCL
@@ -539,14 +541,6 @@
- cna: Google
- anyOf:
- product: Gemini
-- reason: Grafana Labs
- allOf:
- - cna: GRAFANA
- - anyOf:
- - product: Grafana
- - product: Grafana Enterprise
- - product: Grafana OSS
- - product: Snowflake Datasource
- reason: Hashicorp products not packaged in Debian
allOf:
- cna: HashiCorp
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d63cfd1557554939c4239f89285049690ede3cfa
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d63cfd1557554939c4239f89285049690ede3cfa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/22757e4a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list