Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
be8778f4 by Moritz Muehlenhoff at 2026-07-02T09:55:53+02:00
auto-nfu: Add rulefor Craft CMS
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -43,15 +43,15 @@ CVE-2026-57264 (GeoWebPlayer (also called "Web Plugin" in
the GV-VMS documentati
CVE-2026-55886 (Jodit Editor is a WYSIWYG editor with written in pure
TypeScript file ...)
NOT-FOR-US: Jodit Editor
CVE-2026-55794 (Craft CMS is a content management system (CMS). In versions
5.9.0 and ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55793 (Craft CMS is a content management system (CMS). In versions
5.0.0-RC1 ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55792 (Craft CMS is a content management system (CMS). In versions
starting f ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55791 (Craft CMS is a content management system (CMS). Versions
4.0.0-RC1 and ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55790 (Craft CMS is a content management system (CMS). In versions
5.0.0-RC1 ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55688 (The AsyncHttpClient (AHC) library allows Java applications to
easily e ...)
- async-http-client <unfixed>
NOTE:
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f
@@ -97,13 +97,13 @@ CVE-2026-52186 (SQL Injection vulnerability in UTT nv518G
nv518GV3v3.2.7-210919-
CVE-2026-50521 (Use after free in Microsoft Edge (Chromium-based) allows an
authorized ...)
NOT-FOR-US: Microsoft
CVE-2026-50284 (Craft CMS is a content management system (CMS). In versions
5.0.0-RC1 ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-50283 (Craft CMS is a content management system (CMS). Versions
5.0.0-RC1 thr ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-50280 (Craft CMS is a content management system (CMS). In versions
5.0.0-RC1 ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-50279 (Craft CMS is a content management system (CMS). IN versions
5.0.0-RC1 ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-49858 (API Platform Core is a system to create hypermedia-driven REST
and Gra ...)
TODO: check
CVE-2026-38891 (An improper input validation in the gazebo_ros_diff_drive.cpp
componen ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -875,12 +875,14 @@
description: '.*\bBelkin\b.*'
- reason: Bento4
description: '.*\bBento4\b.*'
+- reason: Campcodes
+ description: '.*\b(?i:campcodes)\s.*\s(?i:(system|portal))\b.*'
- reason: Chamilo LMS
description: '.*\b(?i:Chamilo LMS)\b.*'
- reason: CodeAstro
description: '.*\b(?i:Code\s?Astro)\s.*\s(?i:(system))\b.*'
-- reason: Campcodes
- description: '.*\b(?i:campcodes)\s.*\s(?i:(system|portal))\b.*'
+- reason: Craft CMS or plugin for Craft CMS
+ description: '.*\b(?i:Craft CMS)\b.*'
- reason: ChurchCRM
description: '.*\b(?i:ChurchCRM)\b.*'
- reason: code-projects
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be8778f40d0312c49fd76541ae5f42e842b8d5f2
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be8778f40d0312c49fd76541ae5f42e842b8d5f2
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits