[Git][security-tracker-team/security-tracker][master] various issues in ITPed packages

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 22 08:23:06 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b828c462 by Moritz Muehlenhoff at 2026-09-22T09:22:35+02:00
various issues in ITPed packages

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -67,11 +67,11 @@ CVE-2026-94412 (jshERP through 3.6 contains an authorization bypass vulnerabilit
 CVE-2026-94411 (jshERP 3.6 contains a privilege escalation vulnerability in the update ...)
 	TODO: check
 CVE-2026-94404 (MISP has a security issue that could let an attacker change threat-int ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-94403 (A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This i ...)
 	TODO: check
 CVE-2026-94401 (MISP has a file-handling vulnerability that could let certain authenti ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-94394 (When a regular user adds a reference between objects or attributes, MI ...)
 	TODO: check
 CVE-2026-94393 (When a user creates or edits a report inside an event, MISP can identi ...)
@@ -79,21 +79,21 @@ CVE-2026-94393 (When a user creates or edits a report inside an event, MISP can
 CVE-2026-94387 (Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnera ...)
 	TODO: check
 CVE-2026-94383 (The MISP blocklist workflow module accepted a user-supplied blocklist  ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-94382 (Beszel before 0.19.0 contains an insecure direct object reference vuln ...)
 	TODO: check
 CVE-2026-94381 (MISP has a security issue that can let a user gain more access than th ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-94379 (The login() function in MISP's UsersController.php contained insuffici ...)
 	TODO: check
 CVE-2026-94374 (MISP contains an insecure direct object reference vulnerability in the ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-94373 (MISP contains a DOM-based cross-site scripting (XSS) vulnerability in  ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-94372 (MISP contains a stored cross-site scripting (XSS) vulnerability in the ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-94277 (MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxy ...)
-	TODO: check
+	- misp <itp> (bug #1144317)
 CVE-2026-94216 (A vulnerability was determined in ST Engineering iDirect Evolution and ...)
 	TODO: check
 CVE-2026-94214 (A vulnerability was found in ST Engineering iDirect Evolution and Velo ...)
@@ -197,7 +197,7 @@ CVE-2026-87858 (Temporal Server decided whether a Workflow completion callback w
 CVE-2026-86802 (The To Do List Member WordPress plugin through 1.6 does not have autho ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-86473 (Apache Airflow: the Core API logout endpoint revokes only a session to ...)
-	TODO: check
+	- airflow <itp> (bug #819700)
 CVE-2026-85751 (Mailu is a mail server distributed as a set of Docker images. From Mai ...)
 	TODO: check
 CVE-2026-85653 (The Contextual Related Posts plugin for WordPress is vulnerable to Sto ...)
@@ -221,7 +221,7 @@ CVE-2026-83621 (ntopng is a web-based network traffic monitoring application. Pr
 CVE-2026-82412 (ntopng is a web-based network traffic monitoring application. Prior to ...)
 	TODO: check
 CVE-2026-82355 (When a request to the Airflow core API carries both a session cookie a ...)
-	TODO: check
+	- airflow <itp> (bug #819700)
 CVE-2026-82165 (Dell Command | Integration Suite for System Center, versions prior to  ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-82163 (Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contai ...)
@@ -289,11 +289,11 @@ CVE-2026-76974 (SAP Fiori Launchpad does not sufficiently validate certain user-
 CVE-2026-76898 (draw.io is a configurable diagramming and whiteboarding application. P ...)
 	TODO: check
 CVE-2026-75158 (Apache Airflow's `/assets/events` API returned asset events for every  ...)
-	TODO: check
+	- airflow <itp> (bug #819700)
 CVE-2026-71543 (OpenBao is an open source identity-based secrets management system. Pr ...)
-	TODO: check
+	- openbao <itp> (bug #1069794)
 CVE-2026-69190 (Graylog is a free and open log management platform. From 6.3.0 until 6 ...)
-	TODO: check
+	- graylog2 <itp> (bug #652273)
 CVE-2026-68919 (GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD do ...)
 	TODO: check
 CVE-2026-67827 (Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b828c462f7114f5dba44c7b37b007ae86bd73410

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b828c462f7114f5dba44c7b37b007ae86bd73410
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/b437fd36/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list