[Git][security-tracker-team/security-tracker][master] Add CNA rule for check-mk

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 6 11:08:14 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a84096d0 by Moritz Muehlenhoff at 2026-09-06T12:07:09+02:00
Add CNA rule for check-mk

src:check-mk was removed seven years ago and won' come back. The rule
needs to be for products, since they also develop nagvis, which is
packaged in Debian.

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -1060,7 +1060,7 @@ CVE-2026-16180 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1
 CVE-2026-15984 (The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site S ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15937 (Improper certificate validation in Checkmk <2.5.0p10 allows a relay an ...)
-	TODO: check
+	NOT-FOR-US: Checkmk
 CVE-2026-15247 (The Search Atlas SEO  WordPress plugin before 2.6.24 does not perform  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14975 (The WP File Download plugin for WordPress is vulnerable to Directory T ...)
@@ -104361,7 +104361,7 @@ CVE-2024-51394 (Buffer Overflow vulnerability in Ardupiot Copter Latest commit 9
 CVE-2024-48519 (Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b04516 ...)
 	NOT-FOR-US: Ardupiot Copter
 CVE-2024-47091 (Privilege escalation in the mk_mysql agent plugin on Windows in Checkm ...)
-	TODO: check
+	NOT-FOR-US: Checkmk
 CVE-2020-37226 (Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerabi ...)
 	NOT-FOR-US: Joomla addon
 CVE-2020-37225 (Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scr ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -429,6 +429,11 @@
       - product: Check Point SmartConsole
       - product: Identity Agent
       - product: Identity Awareness
+- reason: Checkmk
+  allOf:
+    - cna: Checkmk
+    - anyOf:
+      - product: Checkmk
 - reason: Cisco
   allOf:
     - cna: cisco



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a84096d06f69c0773177e5a20f0d39cf90bfbaca

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a84096d06f69c0773177e5a20f0d39cf90bfbaca
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/4218ce27/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list