[Git][security-tracker-team/security-tracker][master] Add new python-git issue
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 26 21:03:18 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5c8aaf37 by Salvatore Bonaccorso at 2026-09-26T22:02:54+02:00
Add new python-git issue
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -116,7 +116,9 @@ CVE-2026-100690 (Hugo versions from v0.161.0 through v0.165.0 run Node.js tools
- hugo 0.166.0-1
NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-x3mx-cm49-8m9c
CVE-2026-100689 (GitPython before 3.1.62 does not validate the `path` field read from a ...)
- TODO: check
+ - python-git 3.1.62-1
+ NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-59cr-6r3x-644w
+ NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/1ed0ebc2f2e74d979cdc367a4864a7731fdcc093 (3.1.62)
CVE-2026-100688 (Budibase server before 3.45.0 contains a cross-tenant information disc ...)
NOT-FOR-US: Budibase
CVE-2026-100687 (Budibase Server before 3.45.0 fails to redact plaintext datasource cre ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5c8aaf3793447d2bb50c7e4b12a8475b40963b04
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5c8aaf3793447d2bb50c7e4b12a8475b40963b04
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/4706424c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list