[Git][security-tracker-team/security-tracker][master] 3 commits: auto-nfu: Add another roduct for Apache CNA rule

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 19 06:57:06 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5032bd5e by Salvatore Bonaccorso at 2026-09-19T07:55:31+02:00
auto-nfu: Add another roduct for Apache CNA rule

- - - - -
94c467cc by Salvatore Bonaccorso at 2026-09-19T07:56:19+02:00
auto-nfu: Add another covered product for Eclipse CNA rule

- - - - -
38ee9950 by Salvatore Bonaccorso at 2026-09-19T07:56:39+02:00
Process some NFUs

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -1342,7 +1342,7 @@ CVE-2026-92758 (If logging mode is set to DEBUG or a malformed MongoDB connectio
 CVE-2026-92756 (Applications built on MongoDB Entity Framework Core Provider which com ...)
 	NOT-FOR-US: MongoDB Entity Framework
 CVE-2026-92611 (In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches`  ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-92230 (Apache Karaf's XmlUtils cached XML parser/transformer factories in sta ...)
 	- apache-karaf <itp> (bug #881297)
 CVE-2026-91039 (Authentication Bypass by Spoofing vulnerability in team-alembic ash_au ...)
@@ -4105,7 +4105,7 @@ CVE-2026-88792 (The Dictionary WordPress plugin through 1.0 does not have author
 CVE-2026-88592 (kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF ...)
 	NOT-FOR-US: kkFileView
 CVE-2026-87976 (Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipula ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-87963 (The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or pa ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87935 (The Paid Downloads plugin for WordPress is vulnerable to Arbitrary Fil ...)
@@ -10554,7 +10554,7 @@ CVE-2026-87779 (Insertion of sensitive information into log file vulnerability i
 CVE-2026-87087
 	REJECTED
 CVE-2026-86836 (In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates wor ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-86830 (Incorrect privilege assignment in Temporary Elevated Access Management ...)
 	NOT-FOR-US: Amazon
 CVE-2026-86460 (Cypher injection vulnerability in the Neo4j persistence layer when pro ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -412,6 +412,7 @@
       - product: Apache Mynewt NimBLE
       - product: Apache Neethi
       - product: Apache NiFi
+      - product: Apache NiFi Registry
       - product: Apache NimBLE
       - product: Apache Nutch
       - product: Apache NuttX RTOS
@@ -507,12 +508,12 @@
     - cna: eclipse
     - anyOf:
       - product: Eclipse 4diac
-      - product: Eclipse aeriOS
+      - product: Eclipse Ankaios
       - product: Eclipse Arrowhead
       - product: Eclipse BaSyx
       - product: Eclipse BaSyx Go Components
-      - product: Eclipse Che
       - product: Eclipse CSI - PIA
+      - product: Eclipse Che
       - product: Eclipse Cyclone DDS
       - product: Eclipse Ditto
       - product: Eclipse GlassFish
@@ -523,6 +524,7 @@
       - product: Eclipse OMR
       - product: Eclipse OpenJ9
       - product: Eclipse Parsson
+      - product: Eclipse aeriOS
       - product: Eclipse Theia
       - product: Eclipse ThreadX
       - product: Eclipse ThreadX - NetX Duo



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ad36f9d1c829b7faddfef9906c31c261dfaa605a...38ee99503bb6d38a42a68f9de51c742dbe1e820a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ad36f9d1c829b7faddfef9906c31c261dfaa605a...38ee99503bb6d38a42a68f9de51c742dbe1e820a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/9336d7ca/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list