[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 4 13:41:59 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2b171171 by Salvatore Bonaccorso at 2026-09-04T14:41:27+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -228,17 +228,17 @@ CVE-2026-79631 (The WPFunnels  WordPress plugin before 3.13.0 does not restrict
 CVE-2026-79630 (The WPFunnels  WordPress plugin before 3.13.0 does not verify that the ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77465 (toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0 ...)
-	TODO: check
+	NOT-FOR-US: toml-node
 CVE-2026-75754 (Missing Authentication for Critical Function, Server-Side Request Forg ...)
 	NOT-FOR-US: ASUS
 CVE-2026-74853 (The Pods  WordPress plugin before 3.3.9.2 does not restrict which func ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-71429 (stream-json is a micro-library of stream components for processing JSO ...)
-	TODO: check
+	NOT-FOR-US: stream-json
 CVE-2026-71216 (PagerDuty alarm hook transmits the integration routing key over cleart ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-70403 (XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Any ...)
-	TODO: check
+	NOT-FOR-US: XING CPTrans-ME-X
 CVE-2026-70352 (Missing authentication for critical function in Azure AI Language allo ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-70178 (Missing authorization in Microsoft Fabric allows an authorized attacke ...)
@@ -246,15 +246,15 @@ CVE-2026-70178 (Missing authorization in Microsoft Fabric allows an authorized a
 CVE-2026-69857 (Authorization bypass through user-controlled key in Azure Cosmos DB al ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-69657 (XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyon ...)
-	TODO: check
+	NOT-FOR-US: XING CPTrans-ME-X
 CVE-2026-67402 (An insecure Apache configuration in ConfigServer Security & Firewall m ...)
-	TODO: check
+	NOT-FOR-US: ConfigServer Security & Firewall
 CVE-2026-67398 (Missing authorization vulnerability has been discovered in 2Checkout p ...)
-	TODO: check
+	NOT-FOR-US: WHMCS
 CVE-2026-67397 (Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0 ...)
-	TODO: check
+	NOT-FOR-US: Plesk
 CVE-2026-66840 (XING CPTrans-ME-X contains an Exposure of Sensitive System Information ...)
-	TODO: check
+	NOT-FOR-US: XING CPTrans-ME-X
 CVE-2026-65818 (Server-side request forgery (ssrf) in Power Automate allows an authori ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-64200 (There is an out-of-bounds read vulnerability in DASYLab due to imprope ...)
@@ -703,11 +703,11 @@ CVE-2026-82299 (Incorrect Authorization (CWE-863) in Kibana can lead to informat
 CVE-2026-82298 (Incorrect Authorization (CWE-863) in Kibana can lead to denial of serv ...)
 	- kibana <itp> (bug #700337)
 CVE-2026-82180 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is ...)
-	TODO: check
+	NOT-FOR-US: Eclipse Arrowhead
 CVE-2026-82024 (LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site  ...)
-	TODO: check
+	NOT-FOR-US: WordPress Plugin
 CVE-2026-82023 (LearnPress WordPress Plugin before 4.4.6 contains a broken object-leve ...)
-	TODO: check
+	NOT-FOR-US: WordPress Plugin
 CVE-2026-81776 (Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 v ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81773 (Unauthenticated Cross Site Scripting (XSS) in  Ninja Forms File Upload ...)
@@ -723,13 +723,13 @@ CVE-2026-81282 (Subscriber Cross Site Scripting (XSS) in Product Variations Swat
 CVE-2026-81281 (Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-80515 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-autho ...)
-	TODO: check
+	NOT-FOR-US: Eclipse Arrowhead
 CVE-2026-80465 (A vulnerability has been identified in Mendix SAML (Mendix 10 compatib ...)
 	NOT-FOR-US: Siemens
 CVE-2026-80254 (Authorization bypass through user-controlled key issue exists in Shize ...)
-	TODO: check
+	NOT-FOR-US: ShizenBox2 (edge-app)
 CVE-2026-80253 (An improper physical access control issue exists in ShizenBox2 (dev-co ...)
-	TODO: check
+	NOT-FOR-US: ShizenBox2
 CVE-2026-79679 (Use of Weak Credentials vulnerability in B&R Industrial Automation Gmb ...)
 	NOT-FOR-US: ABB group
 CVE-2026-78596 (Missing Authorization in Kibana Leading to Unauthorized Modification o ...)
@@ -765,23 +765,23 @@ CVE-2026-76175 (SQL injection vulnerability in the del_check parameter of the /o
 CVE-2026-76174 (Unrestricted file upload vulnerability in the CSV file upload function ...)
 	TODO: check
 CVE-2026-75602 (OpenList a file list program that supports multiple storage. Prior to  ...)
-	TODO: check
+	NOT-FOR-US: OpenList
 CVE-2026-75137 (UpSignOn for Windows before 7.19.0 contains a sensitive data exposure  ...)
-	TODO: check
+	NOT-FOR-US: UpSignOn
 CVE-2026-75136 (UpSignOn for Windows before 7.19.0 contains an insecure credential sto ...)
-	TODO: check
+	NOT-FOR-US: UpSignOn
 CVE-2026-75135 (UpSignOn for Windows before 7.19.0 contains a sensitive data exposure  ...)
-	TODO: check
+	NOT-FOR-US: UpSignOn
 CVE-2026-75134 (SEOWriting plugin for WordPress through 1.12.5 contains a stored cross ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75036 (A security vulnerability was discovered in Fleet's Helm template prepr ...)
-	TODO: check
+	NOT-FOR-US: Rancher Fleet
 CVE-2026-75035 (A flaw was found in Rancher Manager. When a non-administrative caller  ...)
-	TODO: check
+	NOT-FOR-US: Rancher
 CVE-2026-75034 (A flaw was found in Rancher Manager. The SAML assertion replay protect ...)
-	TODO: check
+	NOT-FOR-US: Rancher
 CVE-2026-75033 (A flaw was found in Rancher Manager. Project Secrets were propagated i ...)
-	TODO: check
+	NOT-FOR-US: Rancher
 CVE-2026-74769 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-74768 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
@@ -789,11 +789,11 @@ CVE-2026-74768 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, con
 CVE-2026-73600 (Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-71963 (Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains  ...)
-	TODO: check
+	NOT-FOR-US: Hermes Agent
 CVE-2026-71404 (A flaw was found in Rancher Manager. The GlobalRole controller derived ...)
-	TODO: check
+	NOT-FOR-US: Rancher
 CVE-2026-71403 (A flaw was found in Rancher Manager. The /v3/users update path did not ...)
-	TODO: check
+	NOT-FOR-US: Rancher
 CVE-2026-71224 (A stack overflow vulnerability was found in gfs2-utils. The metadata w ...)
 	- gfs2-utils <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511397
@@ -3643,7 +3643,7 @@ CVE-2026-71257 (Apache Wicket enforces the upload limits configured on a form or
 CVE-2026-70449 (Improper validation of resource URL attributes in Apache Wicket allows ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66047 (ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-63083
 	REJECTED
 CVE-2026-5956 (Improper neutralization of special elements used in an SQL command ('S ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2b171171ddda81673ab3aefd94ed1c99f715b649

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2b171171ddda81673ab3aefd94ed1c99f715b649
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/6d04fcdc/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list