[Git][security-tracker-team/security-tracker][master] 3 commits: auto-nfu: Add another roduct for Apache CNA rule
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 19 06:57:06 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5032bd5e by Salvatore Bonaccorso at 2026-09-19T07:55:31+02:00
auto-nfu: Add another roduct for Apache CNA rule
- - - - -
94c467cc by Salvatore Bonaccorso at 2026-09-19T07:56:19+02:00
auto-nfu: Add another covered product for Eclipse CNA rule
- - - - -
38ee9950 by Salvatore Bonaccorso at 2026-09-19T07:56:39+02:00
Process some NFUs
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -1342,7 +1342,7 @@ CVE-2026-92758 (If logging mode is set to DEBUG or a malformed MongoDB connectio
CVE-2026-92756 (Applications built on MongoDB Entity Framework Core Provider which com ...)
NOT-FOR-US: MongoDB Entity Framework
CVE-2026-92611 (In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-92230 (Apache Karaf's XmlUtils cached XML parser/transformer factories in sta ...)
- apache-karaf <itp> (bug #881297)
CVE-2026-91039 (Authentication Bypass by Spoofing vulnerability in team-alembic ash_au ...)
@@ -4105,7 +4105,7 @@ CVE-2026-88792 (The Dictionary WordPress plugin through 1.0 does not have author
CVE-2026-88592 (kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF ...)
NOT-FOR-US: kkFileView
CVE-2026-87976 (Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipula ...)
- TODO: check
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-87963 (The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or pa ...)
NOT-FOR-US: WordPress plugin
CVE-2026-87935 (The Paid Downloads plugin for WordPress is vulnerable to Arbitrary Fil ...)
@@ -10554,7 +10554,7 @@ CVE-2026-87779 (Insertion of sensitive information into log file vulnerability i
CVE-2026-87087
REJECTED
CVE-2026-86836 (In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates wor ...)
- TODO: check
+ NOT-FOR-US: Eclipse
CVE-2026-86830 (Incorrect privilege assignment in Temporary Elevated Access Management ...)
NOT-FOR-US: Amazon
CVE-2026-86460 (Cypher injection vulnerability in the Neo4j persistence layer when pro ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -412,6 +412,7 @@
- product: Apache Mynewt NimBLE
- product: Apache Neethi
- product: Apache NiFi
+ - product: Apache NiFi Registry
- product: Apache NimBLE
- product: Apache Nutch
- product: Apache NuttX RTOS
@@ -507,12 +508,12 @@
- cna: eclipse
- anyOf:
- product: Eclipse 4diac
- - product: Eclipse aeriOS
+ - product: Eclipse Ankaios
- product: Eclipse Arrowhead
- product: Eclipse BaSyx
- product: Eclipse BaSyx Go Components
- - product: Eclipse Che
- product: Eclipse CSI - PIA
+ - product: Eclipse Che
- product: Eclipse Cyclone DDS
- product: Eclipse Ditto
- product: Eclipse GlassFish
@@ -523,6 +524,7 @@
- product: Eclipse OMR
- product: Eclipse OpenJ9
- product: Eclipse Parsson
+ - product: Eclipse aeriOS
- product: Eclipse Theia
- product: Eclipse ThreadX
- product: Eclipse ThreadX - NetX Duo
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ad36f9d1c829b7faddfef9906c31c261dfaa605a...38ee99503bb6d38a42a68f9de51c742dbe1e820a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ad36f9d1c829b7faddfef9906c31c261dfaa605a...38ee99503bb6d38a42a68f9de51c742dbe1e820a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/9336d7ca/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list