[Git][security-tracker-team/security-tracker][master] auto-nfu: Extend Apache rule

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 15 14:22:49 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6b47dd8b by Moritz Muehlenhoff at 2026-09-15T13:55:47+02:00
auto-nfu: Extend Apache rule

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -1149,37 +1149,37 @@ CVE-2026-84445 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.82
 	NOTE: https://github.com/grpc/grpc-go/pull/9367 (v1.82.x backports)
 	NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7 (v1.82.2)
 CVE-2026-84179 (Description    getTopologyPageInfo merged the Nimbus daemon configurat ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82920 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2026-82441 (Description  A submitted topology carries two lists of blobstore keys, ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82439 (Description  The DRPC server kept a map from function name to request  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82438 (Description  Three separate mechanisms allowed a web page on an unrela ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82437 (Description  The Logviewer offers `logs.users` and `logs.groups` so op ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82435 (Description  The worker's Netty message decoder is installed ahead of  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82434 (Description  When ZooKeeper authentication is configured, Storm delibe ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82433 (Description  `getNimbusConf` returned the complete daemon configuratio ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82432 (Description  Nimbus validated `topology.blobstore.map` against the cal ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82431 (Description  `SimpleACLAuthorizer` evaluated the user-level command se ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82430 (Description  When launching a Docker or OCI worker, the setuid-root `w ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82429 (Description  The setuid-root `worker-launcher` binary adjusts ownershi ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82428 (Description  Dependency artifacts uploaded with `storm jar --artifacts ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82427 (Description  A topology's `topology.blobstore.map` lets the submitter  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82426 (Description  Nimbus accepted the `uploadedJarLocation` argument of `su ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82232 (Improper neutralization of special elements used in an SQL command ('S ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82035 (PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path trave ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -418,8 +418,14 @@
       - product: Apache SkyWalking MCP
       - product: Apache Spark
       - product: Apache Storm Client
+      - product: Apache Storm DRPC
+      - product: Apache Storm Logviewer
+      - product: Apache Storm Nimbus
       - product: Apache Storm Prometheus Reporter
       - product: Apache Storm UI
+      - product: Apache Storm Webapp
+      - product: Apache Storm Worker
+      - product: Apache Storm Worker Launcher
       - product: Apache StreamPark
       - product: Apache StreamPipes
       - product: Apache Superset



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6b47dd8be9191e0035b6ffe568536b0b369acb7b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6b47dd8be9191e0035b6ffe568536b0b369acb7b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/806df2e7/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list