[Git][security-tracker-team/security-tracker][master] Convert kibana itp'ed entries to NFU

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 5 05:55:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e9429e2c by Salvatore Bonaccorso at 2026-09-05T06:54:26+02:00
Convert kibana itp'ed entries to NFU

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1444,11 +1444,11 @@ CVE-2026-82525 (Exterro FTK Imager before 8.3 contains an XML external entity (X
 CVE-2026-82524 (UnoPim before 2.1.5 contains an authenticated file upload vulnerabilit ...)
 	NOT-FOR-US: UnoPim
 CVE-2026-82302 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized c ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-82299 (Incorrect Authorization (CWE-863) in Kibana can lead to information di ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-82298 (Incorrect Authorization (CWE-863) in Kibana can lead to denial of serv ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-82180 (In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is ...)
 	NOT-FOR-US: Eclipse Arrowhead
 CVE-2026-82024 (LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site  ...)
@@ -1480,13 +1480,13 @@ CVE-2026-80253 (An improper physical access control issue exists in ShizenBox2 (
 CVE-2026-79679 (Use of Weak Credentials vulnerability in B&R Industrial Automation Gmb ...)
 	NOT-FOR-US: ABB group
 CVE-2026-78596 (Missing Authorization in Kibana Leading to Unauthorized Modification o ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78595 (Missing Authorization in Kibana Leading to Information Disclosure / Mi ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78593 (An insufficiently validated configuration field in Kibana's Cribl inte ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78583 (Incorrect Authorization (CWE-863) in Kibana can lead to privilege esca ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78304
 	REJECTED
 CVE-2026-78080 (Joomla Extension - feenders.de - Unauthenticated SQL injection in JooD ...)
@@ -2029,7 +2029,7 @@ CVE-2026-82522 (libjxl before 0.12 contains an integer underflow vulnerability i
 CVE-2026-82404 (TOON is a compact, human-readable serialization of JSON data for LLM p ...)
 	NOT-FOR-US: TOON
 CVE-2026-82293 (Incorrect Authorization (CWE-863) in the Kibana machine learning featu ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-82223 (Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 v ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81775 (Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 version ...)
@@ -2104,27 +2104,27 @@ CVE-2026-78604 (Incorrect Permission Assignment for Critical Resource (CWE-732)
 CVE-2026-78602 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
 	NOT-FOR-US: Elastic Maps Server
 CVE-2026-78601 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78600 (Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can  ...)
 	NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
 CVE-2026-78599 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78598 (Incorrect Authorization (CWE-863) in the Kibana machine learning featu ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78594 (Improper Handling of Highly Compressed Data (CWE-409) in APM Server ca ...)
 	NOT-FOR-US: APM Server
 CVE-2026-78591 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78590 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78588 (Allocation of Resources Without Limits or Throttling (CWE-770) in File ...)
 	NOT-FOR-US: Filebeat
 CVE-2026-78587 (Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial ...)
 	NOT-FOR-US: Fleet Server
 CVE-2026-78586 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78584 (Observable Response Discrepancy (CWE-204) in the Kibana Osquery featur ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78410 (A flaw was found in util-linux. Restricted bind mounts take the source ...)
 	- util-linux 2.42.3-1
 	[trixie] - util-linux <no-dsa> (Minor issue)
@@ -2535,19 +2535,19 @@ CVE-2026-79621 (The CatalogX  WordPress plugin before 6.1.3 does not sanitise or
 CVE-2026-78657 (The SigmaForms Pro \u2013 AI Generated Forms plugin for WordPress is v ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78608 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78607 (Missing Authorization (CWE-862) in the Elasticsearch custom inference  ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-78606 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized d ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78605 (Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling' ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-78603 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78597 (Missing Authorization (CWE-862) in the Kibana Entity Store feature can ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78592 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78151 (The FormLayer WordPress plugin before 1.0.9 does not perform any autho ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77792 (The RegistrationMagic  WordPress plugin before 6.0.9.9 does not escape ...)
@@ -2751,21 +2751,21 @@ CVE-2026-73700 (A vulnerability in the web-based management interface of HPE Net
 CVE-2026-73524 (Cypht before 2.12.2 contains a cross-site scripting vulnerability in t ...)
 	NOT-FOR-US: Cypht
 CVE-2026-72682 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72654 (Execution with Unnecessary Privileges (CWE-250) in the Kibana machine  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72652 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72649 (Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machi ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72644 (Uncaught Exception (CWE-248) in Kibana can lead to a denial of service ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72641 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized m ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72633 (Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72628 (Improper Handling of Highly Compressed Data (CWE-409) in Kibana can le ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-71981 (Cypht before 2.12.2 contains a PHP object injection vulnerability that ...)
 	NOT-FOR-US: Cypht
 CVE-2026-63435 (Mail is an internet library for Ruby designed to handle email generati ...)
@@ -2774,9 +2774,9 @@ CVE-2026-63435 (Mail is an internet library for Ruby designed to handle email ge
 	NOTE: https://github.com/mikel/mail/pull/1664
 	NOTE: Fixed by: https://github.com/mikel/mail/commit/f9d59c2e447af42e2c3dec5a56b1bb25c7292859 (2.9.1)
 CVE-2026-63138 (Improper Neutralization of Special Elements in Data Query Logic (CWE-9 ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-63137 (Incorrect Authorization (CWE-863) in Kibana can lead to privilege esca ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-56143 (Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-45221 (Konga before 2.1.0 contains a privilege escalation vulnerability that  ...)
@@ -2786,7 +2786,7 @@ CVE-2026-3851 (The Divi theme for WordPress is vulnerable to Stored Cross-Site S
 CVE-2026-3850 (The Divi theme for WordPress is vulnerable to Stored Cross-Site Script ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-33465 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-19766 (An authentication bypass vulnerability exists in the underlying operat ...)
 	NOT-FOR-US: HPE
 CVE-2026-19754 (Baserow 2.3.3 contains a SQL injection vulnerability in the index() fo ...)
@@ -11026,7 +11026,7 @@ CVE-2026-78701 (A flaw was found in 389-ds-base. A remote, authenticated attacke
 CVE-2026-78684 (vLLM before 0.27.0 fails to properly classify DeepStream as a GPU back ...)
 	- vllm <itp> (bug #1095237)
 CVE-2026-78581 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-78576
 	REJECTED
 CVE-2026-78572
@@ -26577,61 +26577,61 @@ CVE-2026-72684 (A flaw in Elasticsearch allows an authenticated user holding onl
 CVE-2026-72683 (A flaw in Elasticsearch allows an authenticated user with the privileg ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72681 (Kibana Agent Builder does not correctly verify that the requesting use ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72680 (Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72679 (Elasticsearch does not apply its configurable input length restriction ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72678 (Elasticsearch does not validate a size value taken from a user-supplie ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72677 (Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorize ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72676 (Improper Control of Generation of Code ('Code Injection') (CWE-94) in  ...)
 	NOT-FOR-US: Fleet Server
 CVE-2026-72675 (Missing Authorization (CWE-862) in Kibana can lead to cross-space info ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72674 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72673 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized d ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72672 (The Elastic Security capability that suggests existing field values wh ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72671 (A Kibana Machine Learning capability that removes a saved object from  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72670 (A lower privileged user who holds only the privilege to read agent pol ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72669 (The state that Kibana stores for an Observability Onboarding flow is n ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72667 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72666 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72665 (Missing Authorization (CWE-862) in Kibana can lead to unauthorized exe ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72664 (Missing Authorization (CWE-862) in Kibana can lead to unauthorized exe ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72663 (Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to den ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72661 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72660 (Uncaught Exception (CWE-248), resulting from Improper Input Validation ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72659 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72658 (Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege e ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72657 (Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Se ...)
 	NOT-FOR-US: Fleet Server
 CVE-2026-72656 (Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL que ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72655 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72653 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72651 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72650 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72648 (Cleartext Storage of Sensitive Information in an Environment Variable  ...)
 	NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
 CVE-2026-72647 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial o ...)
@@ -26639,7 +26639,7 @@ CVE-2026-72647 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to de
 CVE-2026-72645 (Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72643 (Kibana Agent Builder determines whether a caller owns a private agent  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72642 (The native inference process that Elasticsearch uses to evaluate uploa ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72640 (The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret  ...)
@@ -26651,21 +26651,21 @@ CVE-2026-72638 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to de
 CVE-2026-72636 (Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matchin ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72632 (Observable Discrepancy (CWE-203) in Kibana Fleet can lead to informati ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72631 (Improper Privilege Management (CWE-269) in Kibana Fleet can lead to pr ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72630 (Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privileg ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-72629 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-59714 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
 	NOT-FOR-US: Open WebUI
 CVE-2026-49864 (wetty provides terminal access in browser over http/https. Prior to ve ...)
 	NOT-FOR-US: wetty
 CVE-2026-49096 (Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of ser ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-49089 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-45774 (compliance-trestle is a tooling platform for managing compliance as co ...)
 	NOT-FOR-US: compliance-trestle
 CVE-2026-45725 (compliance-trestle is a tooling platform for managing compliance as co ...)
@@ -49050,27 +49050,27 @@ CVE-2026-63358 (FileGator accepts arbitrary Unix permission values via the '/chm
 CVE-2026-63263 (Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead  ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-63262 (Missing Authorization (CWE-862) in Kibana can lead to unauthorized cro ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-63261 (Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to deni ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-63260 (Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to deni ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-63259 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-63145 (Incorrect Authorization (CWE-863) in Kibana can lead to integrity comp ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-63144 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial o ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-63143 (Missing Authorization (CWE-862) in Kibana can lead to unauthorized inf ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-63142 (Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-63141 (Missing Authorization (CWE-862) in Kibana allows an authenticated user ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-63140 (Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of s ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-63139 (Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to deni ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-63136 (Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead  ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-63092 (kirby-modules through 5.5.7, fixed in commit 315417e, contains an info ...)
@@ -51128,9 +51128,9 @@ CVE-2026-56745 (Netty is a network application framework for development of prot
 	NOTE: Fixed by: https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b (netty-4.2.16.Final)
 	NOTE: Fixed by: https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 (netty-4.1.136.Final)
 CVE-2026-56147 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-56146 (Improper Access Control (CWE-284) in Kibana can lead to unauthorized m ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-56145 (Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead  ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-56144 (Incorrect Authorization (CWE-863) in Elasticsearch can allow an authen ...)
@@ -51163,7 +51163,7 @@ CVE-2026-50756 (An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote a
 CVE-2026-50755 (An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacke ...)
 	NOT-FOR-US: DayuanJiang next-ai-draw-io
 CVE-2026-49092 (Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-47731 (The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instrument ...)
 	NOT-FOR-US: NASA AMMOS Instrument Toolkit
 CVE-2026-47708 (MCP-for-Stata is an MCP server for Stata to integrate Stata into an ag ...)
@@ -51392,7 +51392,7 @@ CVE-2026-43946 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard)
 CVE-2026-43945 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
 	NOT-FOR-US: FUXA
 CVE-2026-42397 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-3821 (Supermicro (SMC) SMASH services contain an Arbitrary code execution is ...)
 	NOT-FOR-US: Supermicro
 CVE-2026-35290 (Vulnerability in Oracle Application Testing Suite.   The supported ver ...)
@@ -66841,7 +66841,7 @@ CVE-2026-57516 (Ray prior to 2.56.0 contains an unsafe deserialization vulnerabi
 CVE-2026-56152 (Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauth ...)
 	NOT-FOR-US: Elastic Defend
 CVE-2026-56151 (Improper Input Validation (CWE-20) in Kibana can lead to a denial of s ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-56150 (Allocation of Resources Without Limits or Throttling (CWE-770) in Flee ...)
 	NOT-FOR-US: Fleet Server
 CVE-2026-56149 (Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...)
@@ -66945,13 +66945,13 @@ CVE-2026-50043 (Improper neutralization of special elements used in an OS comman
 CVE-2026-49119 (Gradio before 6.16.0 contain a path traversal vulnerability in the Fil ...)
 	NOT-FOR-US: Gradio
 CVE-2026-49091 (Improper Output Neutralization for Logs (CWE-117) in Kibana can lead t ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-49090 (Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead  ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-49088 (Insertion of Sensitive Information into Log File (CWE-532) in Kibana c ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-49087 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-46680 (containerd is an open-source container runtime. In versions prior to 1 ...)
 	- containerd <unfixed> (bug #1141499)
 	NOTE: https://github.com/containerd/containerd/security/advisories/GHSA-fqw6-gf59-qr4w
@@ -92614,11 +92614,11 @@ CVE-2026-49127 (Music Player Daemon (MPD) before version 0.24.11 contains a stac
 	NOTE: https://github.com/MusicPlayerDaemon/MPD/issues/2485
 	NOTE: Fixed by: https://github.com/MusicPlayerDaemon/MPD/commit/59911028c020f84bc2e669da6a1ef88121301274 (v0.24.11)
 CVE-2026-49095 (Improper Input Validation (CWE-20) in the Kibana Fleet agent policy ma ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-49094 (Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to deni ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-49093 (Server-Side Request Forgery (CWE-918) in Kibana can allow an authentic ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-48116 (AnythingLLM is an application that turns pieces of content into contex ...)
 	NOT-FOR-US: AnythingLLM
 CVE-2026-47713 (AnythingLLM is an application that turns pieces of content into contex ...)
@@ -92714,13 +92714,13 @@ CVE-2026-44657 (Mantis Bug Tracker (MantisBT) is an open source issue tracker. P
 CVE-2026-44655 (Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1. ...)
 	- mantis <removed>
 CVE-2026-42401 (Improper Neutralization of Input During Web Page Generation (CWE-79) i ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-42400 (Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to deni ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-42399 (Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to deni ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-42398 (Server-Side Request Forgery (CWE-918) in Kibana allows authenticated u ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-42071 (Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2. ...)
 	- mantis <removed>
 CVE-2026-42070 (Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior t ...)
@@ -92738,11 +92738,11 @@ CVE-2026-34311 (Vulnerability in the Oracle Hospitality OPERA 5 Property Service
 CVE-2026-33590 (Insecure default settings of Portainer CE grant regular (non-admin) us ...)
 	NOT-FOR-US: Portainer
 CVE-2026-33464 (Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a de ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-33463 (Operation on a Resource after Expiration or Termination (CWE-672) in K ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-33462 (A path traversal vulnerability was identified in Kibana's dashboard ma ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-32847 (DeepCode through commit c991dc2 contains a path traversal vulnerabilit ...)
 	NOT-FOR-US: DeepCode
 CVE-2026-2128 (The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive ...)
@@ -125485,13 +125485,13 @@ CVE-2026-33753 (rfc3161-client is a Python library implementing the Time-Stamp P
 CVE-2026-33466 (Improper Limitation of a Pathname to a Restricted Directory (CWE-22) i ...)
 	- logstash <itp> (bug #664841)
 CVE-2026-33461 (Incorrect Authorization (CWE-863) in Kibana can lead to information di ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-33460 (Incorrect Authorization (CWE-863) in Kibana can lead to cross-space in ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-33459 (Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to deni ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-33458 (Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-33350 (LORIS (Longitudinal Online Research and Imaging System) is a self-host ...)
 	NOT-FOR-US: LORIS (Longitudinal Online Research and Imaging System)
 CVE-2026-33229 (XWiki Platform is a generic wiki platform offering runtime services fo ...)
@@ -137660,9 +137660,9 @@ CVE-2026-27065 (Improper Control of Filename for Include/Require Statement in PH
 CVE-2026-27043 (Unrestricted Upload of File with Dangerous Type vulnerability in Theme ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-26940 (Improper Validation of Specified Quantity in Input (CWE-1284) in the T ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-26939 (Missing Authorization (CWE-862) in Kibana\u2019s server-side Detection ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-26933 (Improper Validation of Array Index (CWE-129) in multiple protocol pars ...)
 	- packetbeat <itp> (bug #806484)
 CVE-2026-26931 (Memory Allocation with Excessive Size Value (CWE-789) in the Prometheu ...)
@@ -146741,15 +146741,15 @@ CVE-2026-26979 (Discourse is an open source discussion platform. Prior to versio
 CVE-2026-26973 (Discourse is an open source discussion platform. Versions prior to 202 ...)
 	NOT-FOR-US: Discourse
 CVE-2026-26938 (Improper Neutralization of Special Elements Used in a Template Engine  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-26937 (Uncontrolled Resource Consumption (CWE-400) in the Timelion component  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-26936 (Inefficient Regular Expression Complexity (CWE-1333) in the AI Inferen ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-26935 (Improper Input Validation (CWE-20) in the internal Content Connectors  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-26934 (Improper Validation of Specified Quantity in Input (CWE-1284) in Kiban ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-26932 (Improper Validation of Array Index (CWE-129) in the PostgreSQL protoco ...)
 	- packetbeat <itp> (bug #806484)
 CVE-2026-26682 (An issue in fastCMS before v.0.1.6 allows a local attacker to execute  ...)
@@ -164559,7 +164559,7 @@ CVE-2026-22036 (Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.
 CVE-2026-21889 (Weblate is a web based localization tool. Prior to 5.15.2, the screens ...)
 	- weblate <itp> (bug #745661)
 CVE-2026-0532 (External Control of File Name or Path (CWE-73) combined with Server-Si ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-0529 (Improper Validation of Array Index (CWE-129) in Packetbeat\u2019s Mong ...)
 	- packetbeat <itp> (bug #806484)
 CVE-2025-9142 (A local user can trigger Harmony SASE Windows client to write or delet ...)
@@ -164888,11 +164888,11 @@ CVE-2026-0635 (The Responsive Accordion Slider plugin for WordPress is vulnerabl
 CVE-2026-0594 (The List Site Contributors plugin for WordPress is vulnerable to Refle ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-0543 (Improper Input Validation (CWE-20) in Kibana's Email Connector can all ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-0531 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-0530 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2026-0528 (Improper Validation of Array Index (CWE-129) exists in Metricbeat can  ...)
 	NOT-FOR-US: Elastic Metricbeat
 CVE-2025-68970 (Permission verification bypass vulnerability in the media library modu ...)
@@ -175973,21 +175973,21 @@ CVE-2025-68484
 CVE-2025-68483
 	REJECTED
 CVE-2025-68422 (Improper Authorization (CWE-285) in Kibana can lead to privilege escal ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-68398 (Weblate is a web based localization tool. In versions prior to 5.15.1, ...)
 	- weblate <itp> (bug #745661)
 CVE-2025-68390 (Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...)
 	- elasticsearch <removed>
 CVE-2025-68389 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-68388 (Allocation of resources without limits or throttling (CWE-770) allows  ...)
 	- packetbeat <itp> (bug #806484)
 CVE-2025-68387 (Improper neutralization of input during web page generation ('Cross-si ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-68386 (Improper Authorization (CWE-285) in Kibana can lead to privilege escal ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-68385 (Improper neutralization of input during web page generation ('Cross-si ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-68384 (Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...)
 	- elasticsearch <removed>
 CVE-2025-68383 (Improper Validation of Specified Index, Position, or Offset in Input ( ...)
@@ -178931,7 +178931,7 @@ CVE-2025-55703 (An error-based SQL injection vulnerability exists in the Sunbird
 CVE-2025-51962 (A HTML Injection vulnerability in the comment section of the project p ...)
 	NOT-FOR-US: MicroStudio
 CVE-2025-37732 (Improper neutralization of input during web page generation ('Cross-si ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-37731 (Improper Authentication in Elasticsearch PKI realm can lead to user im ...)
 	- elasticsearch <removed>
 CVE-2025-36360 (IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3 ...)
@@ -190020,7 +190020,7 @@ CVE-2025-52331 (Cross-site scripting (XSS) vulnerability in the generate report
 CVE-2025-46428 (Dell SmartFabric OS10 Software, versions prior to 10.6.1.0,  contain a ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2025-37734 (Origin Validation Error in Kibana can lead to Server-Side Request Forg ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-27368 (IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of s ...)
 	NOT-FOR-US: IBM
 CVE-2025-25236 (Omnissa Workspace ONE UEM contains an observable response discrepancy  ...)
@@ -200623,9 +200623,9 @@ CVE-2025-37727 (Insertion of sensitive information in log file in Elasticsearch
 CVE-2025-30001 (Incorrect Execution-Assigned Permissions vulnerability in Apache Strea ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2025-25018 (Improper Neutralization of Input During Web Page Generation in Kibana  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-25017 (Improper Neutralization of Input During Web Page Generation in Kibana  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-23309 (NVIDIA Display Driver contains a vulnerability where an uncontrolled D ...)
 	NOT-FOR-US: NVIDIA display drivers for Windows
 CVE-2025-23345 (NVIDIA Display Driver for Windows and Linux contains a vulnerability i ...)
@@ -201916,7 +201916,7 @@ CVE-2025-59425 (vLLM is an inference and serving engine for large language model
 CVE-2025-58712 (A container privilege escalation flaw was found in certain AMQ Broker  ...)
 	NOT-FOR-US: Red Hat AMQ
 CVE-2025-25009 (Improper Neutralization of Input During Web Page Generation in Kibana  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-11419 (A flaw was found in Keycloak. This vulnerability allows an unauthentic ...)
 	- keycloak <itp> (bug #1088287)
 CVE-2025-11429 (A flaw was found in Keycloak. Keycloak does not immediately enforce th ...)
@@ -218140,7 +218140,7 @@ CVE-2025-29364 (spimsimulator spim v9.1.24 and before is vulnerable to Buffer Ov
 	NOTE: https://github.com/Giles-one/spimsimulatorEscape?tab=readme-ov-file#bug2-bypass-check-in-read_syscall-and-write_syscall-leading-to-out-of-bounds-readwrite
 	NOTE: Negligible security impact
 CVE-2025-25010 (Incorrect authorization in Kibana can lead to privilege escalation via ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-0951 (Multiple plugins and/or themes for WordPress by LiquidThemes are vulne ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-9648 (The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file  ...)
@@ -237395,7 +237395,7 @@ CVE-2025-41255 (Cyberduck and Mountain Duck improperly handle TLS certificate pi
 CVE-2025-25905 (Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and befor ...)
 	NOT-FOR-US: CADClick
 CVE-2025-25012 (URL redirection to an untrusted site ('Open Redirect') in Kibana can l ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-20282 (A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC coul ...)
 	NOT-FOR-US: Cisco
 CVE-2025-20281 (A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could ...)
@@ -242684,7 +242684,7 @@ CVE-2024-50562 (An Insufficient Session Expiration vulnerability [CWE-613] in Fo
 CVE-2024-45329 (A authorization bypass through user-controlled key in Fortinet FortiPo ...)
 	NOT-FOR-US: Fortinet
 CVE-2024-43706 (Improper authorization in Kibana can lead to privilege abuse via a dir ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-41797 (A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA ...)
 	NOT-FOR-US: Siemens
 CVE-2024-41505 (Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site  ...)
@@ -253119,7 +253119,7 @@ CVE-2025-25218 (in OpenHarmony v5.0.3 and prior versions allow a local attacker
 CVE-2025-25052 (in OpenHarmony v5.0.3 and prior versions allow a local attacker cause  ...)
 	NOT-FOR-US: OpenHarmony
 CVE-2025-25014 (A Prototype pollution vulnerability in Kibana leads to arbitrary code  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-23379 (Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contai ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2025-22886 (in OpenHarmony v5.0.3 and prior versions allow a local attacker case D ...)
@@ -254478,7 +254478,7 @@ CVE-2025-29763
 CVE-2025-27007 (Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoK ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-25016 (Unrestricted file upload in Kibana allows an authenticated attacker to ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-24522 (KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authent ...)
 	NOT-FOR-US: KUNBUS Revolution Pi OS Bookworm
 CVE-2025-23254 (NVIDIA TensorRT-LLM for any platform contains a vulnerability in pytho ...)
@@ -254496,7 +254496,7 @@ CVE-2024-52976 (Inclusion of functionality from an untrusted control sphere in E
 CVE-2024-11994 (APM server logs could contain parts of the document body from a partia ...)
 	NOT-FOR-US: APM server
 CVE-2024-11390 (Unrestricted upload of a file with dangerous type in Kibana can lead t ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2023-46669 (Exposure of sensitive information to local unauthorized actors in Elas ...)
 	NOT-FOR-US: Elastic Agent and Elastic Security Endpoint
 CVE-2022-49931 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
@@ -261837,7 +261837,7 @@ CVE-2024-6857 (The WP MultiTasking  WordPress plugin through 0.1.12 does not hav
 CVE-2024-55354 (Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can  ...)
 	NOT-FOR-US: Lucee
 CVE-2024-12556 (Prototype Pollution in Kibana can lead to code injection via unrestric ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-3437 (The Motors \u2013 Car Dealership & Classified Listings Plugin plugin f ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-3436 (The coreActivity: Activity Logging for WordPress plugin for WordPress  ...)
@@ -262287,7 +262287,7 @@ CVE-2024-52981 (An issue was discovered in Elasticsearch, where a large recursio
 CVE-2024-52980 (A flaw was discovered in Elasticsearch, where a large recursion using  ...)
 	- elasticsearch <removed>
 CVE-2024-52974 (An issue has been identified where a specially crafted request sent to ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-52962 (AnImproper Output Neutralization for Logs vulnerability [CWE-117] in F ...)
 	NOT-FOR-US: Fortinet
 CVE-2024-50565 (A improper restriction of communication channel to intended endpoints  ...)
@@ -273568,7 +273568,7 @@ CVE-2025-27412 (REDAXO is a PHP-based CMS. In Redaxo from 5.0.0 through 5.18.2,
 CVE-2025-27411 (REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/medi ...)
 	NOT-FOR-US: REDAXO
 CVE-2025-25015 (Prototype pollution in Kibana leads to arbitrary code execution via a  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2025-24521 (External XML entity injection allows arbitrary download of files. The  ...)
 	NOT-FOR-US: Keysight
 CVE-2025-24494 (Path traversal may allow remote code execution using privileged accoun ...)
@@ -287785,7 +287785,7 @@ CVE-2024-52325 (ECOVACS robot lawnmowers and vacuums are vulnerable to command i
 CVE-2024-45672 (IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local pr ...)
 	NOT-FOR-US: IBM
 CVE-2024-43708 (An allocation of resources without limits or throttling in Kibana can  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-13593 (The BMLT Meeting Map plugin for WordPress is vulnerable to Local File  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-13511 (The Variation Swatches for WooCommerce plugin, in all versions startin ...)
@@ -287868,11 +287868,11 @@ CVE-2024-56923 (Stored Cross-Site Scripting (XSS) Vulnerability in the Categoriz
 CVE-2024-52975 (An issue was identified in Fleet Server where Fleet policies that coul ...)
 	NOT-FOR-US: Elastic Fleet
 CVE-2024-52972 (An allocation of resources without limits or throttling in Kibana can  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-43710 (A server side request forgery vulnerability was identified in Kibana w ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-43707 (An issue was identified in Kibana where a user without access to Fleet ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-42187 (BigFix Patch Download Plug-ins are affected by path traversal vulnerab ...)
 	NOT-FOR-US: HCL
 CVE-2024-42186 (BigFix Patch Download Plug-ins are affected by an insecure protocol su ...)
@@ -288771,7 +288771,7 @@ CVE-2024-54792 (A Cross-Site Request Forgery (CSRF) vulnerability has been found
 CVE-2024-53829 (CodeChecker is an analyzer tooling, defect database and viewer extensi ...)
 	NOT-FOR-US: CodeChecker
 CVE-2024-52973 (An allocation of resources without limits or throttling in Kibana can  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-51919 (Unrestricted Upload of File with Dangerous Type vulnerability in radyk ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-51888 (Incorrect Privilege Assignment vulnerability in favethemes Homey Login ...)
@@ -308429,7 +308429,7 @@ CVE-2024-3501 (In lunary-ai/lunary versions up to and including 1.2.5, an inform
 CVE-2024-3379 (In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authori ...)
 	NOT-FOR-US: lunary-ai/lunary
 CVE-2024-37285 (A deserialization issue in Kibana can lead to arbitrary code execution ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-2552 (A command injection vulnerability in Palo Alto Networks PAN-OS softwar ...)
 	NOT-FOR-US: Palo Alto Networks PAN-OS
 CVE-2024-2551 (A null pointer dereference vulnerability in Palo Alto Networks PAN-OS  ...)
@@ -326947,7 +326947,7 @@ CVE-2024-42500 (HPE has identified a denial of service vulnerability in HPE HP-U
 CVE-2024-40643 (Joplin is a free, open source note taking and to-do application. Jopli ...)
 	- joplin <itp> (bug #931306)
 CVE-2024-37288 (A deserialization issue in Kibana can lead to arbitrary code execution ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-27387 (An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos ...)
 	NOT-FOR-US: Samsung
 CVE-2024-27383 (An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos ...)
@@ -333359,7 +333359,7 @@ CVE-2024-37968 (Windows DNS Spoofing Vulnerability)
 CVE-2024-37935 (Missing Authorization vulnerability in anhvnit Woocommerce OpenPos all ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-37287 (A flaw allowing arbitrary code execution was discovered in Kibana. An  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-37015 (An issue was discovered in Ada Web Server 20.0. When configured to use ...)
 	NOT-FOR-US: Ada Web Server
 CVE-2024-36505 (An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 th ...)
@@ -336036,7 +336036,7 @@ CVE-2024-39944 (A vulnerability has been found in Dahua products.Attackers can s
 CVE-2024-38983 (Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an att ...)
 	NOT-FOR-US: alykoshin mini-deep-assign
 CVE-2024-37281 (An issue was discovered in Kibana where a user with Viewer role could  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-7264 (libcurl's ASN1 parser code has the `GTime2str()` function, used for pa ...)
 	- curl 8.9.1-1 (bug #1077656)
 	[bookworm] - curl 7.88.1-10+deb12u7
@@ -347164,7 +347164,7 @@ CVE-2024-36979 (In the Linux kernel, the following vulnerability has been resolv
 	[buster] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/3a7c1661ae1383364cd6092d851f5e5da64d476b (6.10-rc1)
 CVE-2024-23443 (A high-privileged user, allowed to create custom osquery packs 17 coul ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-6146 (Actiontec WCB6200Q uh_get_postdata_withupload Stack-based Buffer Overf ...)
 	NOT-FOR-US: Actiontec WCB6200Q
 CVE-2024-6145 (Actiontec WCB6200Q Cookie Format String Remote Code Execution Vulnerab ...)
@@ -347890,7 +347890,7 @@ CVE-2024-2023 (The Folders and Folders Pro plugin for WordPress is vulnerable to
 CVE-2024-24320 (Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 t ...)
 	NOT-FOR-US: Mgt-commerce CloudPanel
 CVE-2024-23442 (An open redirect issue was discovered in Kibana that could lead to a u ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2023-51376 (Missing Authorization vulnerability in Brainstorm Force ProjectHuddle  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-5995 (The notification emails sent by Soar Cloud HR Portal contain a link wi ...)
@@ -350481,7 +350481,7 @@ CVE-2024-37280 (A flaw was discovered in Elasticsearch, affecting document inges
 CVE-2024-23445 (It was identified that if a  cross-cluster API key https://www.elastic ...)
 	- elasticsearch <removed>
 CVE-2024-37279 (A flaw was discovered in Kibana, allowing view-only users of alerting  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-5154 (A flaw was found in cri-o. A malicious container can create a symbolic ...)
 	- cri-o <itp> (bug #979702)
 CVE-2024-5640 (The Prime Slider \u2013 Addons For Elementor (Revolution of a slider,  ...)
@@ -389602,7 +389602,7 @@ CVE-2024-23673 (Malicious code execution via path traversal in Apache Software F
 CVE-2024-23447 (An issue was discovered in the Windows Network Drive Connector when us ...)
 	NOT-FOR-US: Elastic Network Drive Connector
 CVE-2024-23446 (An issue was discovered by Elastic, whereby the Detection Engine Searc ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2024-23344 (Tuleap is an Open Source Suite to improve management of software devel ...)
 	NOT-FOR-US: Tuleap
 CVE-2024-22520 (An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers t ...)
@@ -400839,7 +400839,7 @@ CVE-2023-47536 (An improper access control vulnerability [CWE-284] in FortiOS ve
 CVE-2023-46713 (An improper output neutralization for logs in Fortinet FortiWeb 6.2.0  ...)
 	NOT-FOR-US: FortiGuard
 CVE-2023-46675 (An issue was discovered by Elastic whereby sensitive information may b ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2023-45864 (A race condition issue discovered in Samsung Mobile Processor Exynos 9 ...)
 	NOT-FOR-US: Samsung
 CVE-2023-45801 (Improper Authentication vulnerability in Nadatel DVR allows Informatio ...)
@@ -403933,7 +403933,7 @@ CVE-2023-47038 (A vulnerability was found in perl 5.30.0 through 5.38.0. This is
 	NOTE: Fixed by: https://github.com/Perl/perl5/commit/92a9eb3d0d52ec7655c1beb29999a5a5219be664 (v5.38.1)
 	NOTE: Fixed by: https://github.com/Perl/perl5/commit/ff1f9f59360afeebd6f75ca1502f5c3ebf077da3 (bleed)
 CVE-2023-46671 (An issue was discovered by Elastic whereby sensitive information may b ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2023-6293 (Prototype Pollution in GitHub repository robinbuschmann/sequelize-type ...)
 	NOT-FOR-US: sequelize-typescript
 CVE-2023-6277 (An out-of-memory flaw was found in libtiff. Passing a crafted tiff fil ...)
@@ -408725,7 +408725,7 @@ CVE-2023-38846 (An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker
 CVE-2023-38845 (An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote ...)
 	NOT-FOR-US: Anglaise Company Anglaise.Company
 CVE-2023-31422 (An issue was discovered by Elastic whereby sensitive information is re ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2023-31421 (It was discovered that when acting as TLS clients, Beats, Elastic Agen ...)
 	NOT-FOR-US: Elastic
 CVE-2023-45872 (An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x be ...)
@@ -432204,9 +432204,9 @@ CVE-2023-32233 (In the Linux kernel through 6.3.1, a use-after-free in Netfilter
 	NOTE: https://git.kernel.org/linus/c1592a89942e9678f7d9c8030efa777c0d57edab (6.4-rc1)
 	NOTE: https://www.openwall.com/lists/oss-security/2023/05/15/5
 CVE-2023-31415 (Kibana version 8.7.0 contains an arbitrary code execution flaw. An att ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2023-31414 (Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code executio ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2023-31413 (Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson inp ...)
 	NOT-FOR-US: Filebeat
 CVE-2023-2535
@@ -491874,9 +491874,9 @@ CVE-2022-38781
 CVE-2022-38780
 	RESERVED
 CVE-2022-38779 (An open redirect issue was discovered in Kibana that could lead to a u ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2022-38778 (A flaw (CVE-2022-38900) was discovered in one of Kibana\u2019s third p ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2022-38777 (An issue was discovered in the rollback feature of Elastic Endpoint Se ...)
 	NOT-FOR-US: Elastic Endpoint Security
 CVE-2022-38776
@@ -536531,15 +536531,15 @@ CVE-2022-23713 (A cross-site-scripting (XSS) vulnerability was discovered in the
 CVE-2022-23712 (A Denial of Service flaw was discovered in Elasticsearch. Using this v ...)
 	- elasticsearch <removed>
 CVE-2022-23711 (A vulnerability in Kibana could expose sensitive information related t ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2022-23710 (A cross-site-scripting (XSS) vulnerability was discovered in the Data  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2022-23709 (A flaw was discovered in Kibana in which users with Read access to the ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2022-23708 (A flaw was discovered in Elasticsearch 7.17.0\u2019s upgrade assistant ...)
 	- elasticsearch <removed>
 CVE-2022-23707 (An XSS vulnerability was found in Kibana index patterns. Using this vu ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2022-23706 (A remote cross-site scripting (xss) vulnerability was discovered in HP ...)
 	NOT-FOR-US: HPE OneView
 CVE-2022-23705 (A security vulnerability has been identified in HPE Nimble Storage Hyb ...)
@@ -568640,11 +568640,11 @@ CVE-2021-37940 (An information disclosure via GET request server-side request fo
 CVE-2021-37939 (It was discovered that Kibana\u2019s JIRA connector & IBM Resilient co ...)
 	NOT-FOR-US: IBM
 CVE-2021-37938 (It was discovered that on Windows operating systems specifically, Kiba ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2021-37937 (An issue was found with how API keys are created with the Fleet-Server ...)
 	- elasticsearch <removed>
 CVE-2021-37936 (It was discovered that Kibana was not sanitizing document fields conta ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2021-37935 (An information disclosure vulnerability in the login page of Huntflow  ...)
 	NOT-FOR-US: Huntflow Enterprise
 CVE-2021-37934 (Due to insufficient server-side login-attempt limit enforcement, a vul ...)
@@ -608383,9 +608383,9 @@ CVE-2021-22153 (A Remote Code Execution vulnerability in the Management Console
 CVE-2021-22152 (A Denial of Service due to Improper Input Validation vulnerability in  ...)
 	NOT-FOR-US: BlackBerry UEM
 CVE-2021-22151 (It was discovered that Kibana was not validating a user supplied path, ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2021-22150 (It was discovered that a user with Fleet admin permissions could uploa ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2021-22149 (Elastic Enterprise Search App Search versions before 7.14.0 are vulner ...)
 	NOT-FOR-US: Elastic Enterprise Search
 CVE-2021-22148 (Elastic Enterprise Search App Search versions before 7.14.0 was vulner ...)
@@ -608401,19 +608401,19 @@ CVE-2021-22144 (In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontroll
 CVE-2021-22143 (The Elastic APM .NET Agent can leak sensitive HTTP header information  ...)
 	NOT-FOR-US: Elastic APM .NET Agent
 CVE-2021-22142 (Kibana contains an embedded version of the Chromium browser that the R ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2021-22141 (An open redirect flaw was found in Kibana versions before 7.13.0 and 6 ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2021-22140 (Elastic App Search versions after 7.11.0 and before 7.12.0 contain an  ...)
 	NOT-FOR-US: Elastic App Search web crawler
 CVE-2021-22139 (Kibana versions before 7.12.1 contain a denial of service vulnerabilit ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2021-22138 (In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS ce ...)
 	- logstash <itp> (bug #664841)
 CVE-2021-22137 (In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosu ...)
 	- elasticsearch <removed>
 CVE-2021-22136 (In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session time ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2021-22135 (Elasticsearch versions before 7.11.2 and 6.8.15 contain a document dis ...)
 	- elasticsearch <removed>
 CVE-2021-22134 (A document disclosure flaw was found in Elasticsearch versions after 7 ...)
@@ -669142,7 +669142,7 @@ CVE-2020-10744 (An incomplete fix was found for the fix of the flaw CVE-2020-173
 	NOTE: https://github.com/ansible/ansible/commit/84afa8e90cd168ff13208c8eae3e533ce7e21e1f (v2.9.12)
 	NOTE: CVE is for an incomplete fix of CVE-2020-1733
 CVE-2020-10743 (It was discovered that OpenShift Container Platform's (OCP) distributi ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2020-10742 (A flaw was found in the Linux kernel. An index buffer overflow during  ...)
 	- linux 3.16.2-2
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1835127
@@ -678510,17 +678510,17 @@ CVE-2020-7019 (In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw
 CVE-2020-7018 (Elastic Enterprise Search before 7.9.0 contain a credential exposure f ...)
 	- elasticsearch <removed>
 CVE-2020-7017 (In Kibana versions before 6.8.11 and 7.8.1 the region map visualizatio ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2020-7016 (Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (D ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2020-7015 (Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in t ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2020-7014 (The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch ve ...)
 	- elasticsearch <removed>
 CVE-2020-7013 (Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution f ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2020-7012 (Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2020-7011 (Elastic App Search versions before 7.7.0 contain a cross site scriptin ...)
 	- elasticsearch <removed>
 CVE-2020-7010 (Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate pas ...)
@@ -732890,7 +732890,7 @@ CVE-2019-7623
 CVE-2019-7622
 	RESERVED
 CVE-2019-7621 (Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2019-7620 (Logstash versions before 7.4.1 and 6.8.4 contain a denial of service f ...)
 	NOT-FOR-US: Logstash Beats
 CVE-2019-7619 (Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username  ...)
@@ -732900,7 +732900,7 @@ CVE-2019-7618 (A local file disclosure flaw was found in Elastic Code versions 7
 CVE-2019-7617 (When the Elastic APM agent for Python versions before 5.1.0 is run as  ...)
 	NOT-FOR-US: Elastic APM agent for Python
 CVE-2019-7616 (Kibana versions before 6.8.2 and 7.2.1 contain a server side request f ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2019-7615 (A TLS certificate validation flaw was found in Elastic APM agent for R ...)
 	NOT-FOR-US: Elastic
 CVE-2019-7614 (A race condition flaw was found in the response headers Elasticsearch  ...)
@@ -732912,11 +732912,11 @@ CVE-2019-7612 (A sensitive data disclosure flaw was found in the way Logstash ve
 CVE-2019-7611 (A permission issue was found in Elasticsearch versions before 5.6.15 a ...)
 	- elasticsearch <removed>
 CVE-2019-7610 (Kibana versions before 6.6.1 contain an arbitrary code execution flaw  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2019-7609 (Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code exec ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2019-7608 (Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XS ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2019-7607
 	RESERVED
 CVE-2019-7606
@@ -760040,9 +760040,9 @@ CVE-2018-17248
 CVE-2018-17247 (Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in ...)
 	- elasticsearch <removed>
 CVE-2018-17246 (Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file incl ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2018-17245 (Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2018-17244 (Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the ...)
 	- elasticsearch <removed>
 CVE-2018-17243 (Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows ...)
@@ -796976,7 +796976,7 @@ CVE-2018-3832 (An exploitable firmware update vulnerability exists in Insteon Hu
 CVE-2018-3831 (Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6. ...)
 	- elasticsearch <removed>
 CVE-2018-3830 (Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulner ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2018-3829 (In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was disco ...)
 	NOT-FOR-US: Elastic Cloud Enterprise
 CVE-2018-3828 (Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an info ...)
@@ -796994,13 +796994,13 @@ CVE-2018-3823 (X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cro
 CVE-2018-3822 (X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a u ...)
 	NOT-FOR-US: Elastic X-Pack Security
 CVE-2018-3821 (Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-sit ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2018-3820 (Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scriptin ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2018-3819 (The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2018-3818 (Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (X ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2018-3817 (When logging warnings regarding deprecated settings, Logstash before 5 ...)
 	- logstash <itp> (bug #664841)
 CVE-2017-18017 (The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the  ...)
@@ -825838,13 +825838,13 @@ CVE-2017-11484
 CVE-2017-11483
 	REJECTED
 CVE-2017-11482 (The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pa ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2017-11481 (Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (X ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2017-11480 (Packetbeat versions prior to 5.6.4 are affected by a denial of service ...)
 	- packetbeat <itp> (bug #806484)
 CVE-2017-11479 (Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulner ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2017-11477
 	RESERVED
 CVE-2017-11476
@@ -834899,7 +834899,7 @@ CVE-2015-9058 (Open redirect vulnerability in Proxmox Mail Gateway prior to hotf
 CVE-2015-9057 (Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Ga ...)
 	NOT-FOR-US: Proxmox Mail Gateway
 CVE-2017-8452 (Kibana versions prior to 5.2.1 configured for SSL client access, file  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2017-8451 (With X-Pack installed, Kibana versions before 5.3.1 have an open redir ...)
 	NOT-FOR-US: Kibana addon
 CVE-2017-8450 (X-Pack 5.1.1 did not properly apply document and field level security  ...)
@@ -834907,7 +834907,7 @@ CVE-2017-8450 (X-Pack 5.1.1 did not properly apply document and field level secu
 CVE-2017-8449 (X-Pack Security 5.2.x would allow access to more fields than the user  ...)
 	NOT-FOR-US: Kibana addon
 CVE-2017-8448 (An error was found in the permission model used by X-Pack Alerting 5.0 ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2017-8447 (An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enf ...)
 	NOT-FOR-US: X-Pack plugin for Kibana
 CVE-2017-8446 (The Reporting feature in X-Pack in versions prior to 5.5.2 and standal ...)
@@ -834923,9 +834923,9 @@ CVE-2017-8442 (Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabl
 CVE-2017-8441 (Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not alwa ...)
 	NOT-FOR-US: Elastic X-Pack Security
 CVE-2017-8440 (Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vul ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2017-8439 (Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2017-8438 (Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege es ...)
 	NOT-FOR-US: Elastic X-Pack Security
 CVE-2017-8437
@@ -834983,9 +834983,9 @@ CVE-2017-8419 (LAME through 3.99.5 relies on the signed integer data type for va
 	NOTE: Issue addressed in Debian via: https://sources.debian.org/patches/lame/3.99.5%2Brepack1-9/0001-Add-check-for-invalid-input-sample-rate.patch/
 	NOTE: in the revised version as included in 3.99.5+repack1-7
 CVE-2016-10366 (Kibana versions after and including 4.3 and before 4.6.2 are vulnerabl ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2016-10365 (Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerabi ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2016-10364 (With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not proper ...)
 	NOT-FOR-US: Kibana addon
 CVE-2016-10363 (Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, ...)
@@ -835013,7 +835013,7 @@ CVE-2016-10353
 CVE-2016-10352
 	REJECTED
 CVE-2015-9056 (Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attac ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2017-8905 (Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback,  ...)
 	{DSA-3847-1 DLA-964-1}
 	- xen 4.8.0~rc3-1 (bug #861662)
@@ -866772,9 +866772,9 @@ CVE-2016-1000222 (Logstash prior to version 2.1.2, the CSV output can be attacke
 CVE-2016-1000221 (Logstash prior to version 2.3.4, Elasticsearch Output plugin would log ...)
 	- logstash <itp> (bug #664841)
 CVE-2016-1000220 (Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that wo ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2016-1000219 (Kibana before 4.5.4 and 4.1.11 when a custom output is configured for  ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2016-1000217 (Zotpress plugin for WordPress SQLi in zp_get_account())
 	NOT-FOR-US: WordPress plugin zotpress
 CVE-2016-1000216 (Ruckus Wireless H500 web management interface authenticated command in ...)
@@ -869912,7 +869912,7 @@ CVE-2016-6254 (Heap-based buffer overflow in the parse_packet function in networ
 CVE-2016-6253 (mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, an ...)
 	NOT-FOR-US: mail.local in NetBSD
 CVE-2016-1000218 (Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerab ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2016-1000212 [Mitigation for HTTPoxy vulnerability]
 	{DSA-3642-1 DLA-583-1}
 	- lighttpd 1.4.43-1 (bug #832571)
@@ -891932,7 +891932,7 @@ CVE-2015-8133
 CVE-2015-8132
 	REJECTED
 CVE-2015-8131 (Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kiban ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2015-8130
 	RESERVED
 CVE-2015-8129
@@ -903276,7 +903276,7 @@ CVE-2015-4095
 CVE-2015-4094 (The Thycotic Password Manager Secret Server application through 2.3 fo ...)
 	NOT-FOR-US: Thycotic Password Manager Secret Server application for iOS
 CVE-2015-4093 (Cross-site scripting (XSS) vulnerability in Elasticsearch Kibana 4.x b ...)
-	- kibana <itp> (bug #700337)
+	NOT-FOR-US: Elastic
 CVE-2015-4092 (Buffer overflow in the XComms process in SAP Afaria 7.00.6620.2 SP5 al ...)
 	NOT-FOR-US: SAP Afaria
 CVE-2015-4091 (XML external entity (XXE) vulnerability in SAP NetWeaver AS Java 7.4 a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9429e2c1c7a8f154132dd20d31363d2781ab336

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9429e2c1c7a8f154132dd20d31363d2781ab336
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/032006e0/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list