Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c842100a by Moritz Muehlenhoff at 2026-07-02T12:47:49+02:00
auto-nfu: Add rule for Elastic
elasticsearch was removed eight years ago, no point in tracking as removed
any further.
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -451,7 +451,7 @@ CVE-2026-49119 (Gradio before 6.16.0 contain a path
traversal vulnerability in t
CVE-2026-49091 (Improper Output Neutralization for Logs (CWE-117) in Kibana
can lead t ...)
- kibana <itp> (bug #700337)
CVE-2026-49090 (Uncontrolled Resource Consumption (CWE-400) in Elasticsearch
can lead ...)
- TODO: check
+ NOT-FOR-US: Elasticsearch
CVE-2026-49088 (Insertion of Sensitive Information into Log File (CWE-532) in
Kibana c ...)
- kibana <itp> (bug #700337)
CVE-2026-49087 (Allocation of Resources Without Limits or Throttling (CWE-770)
in Kiba ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -466,6 +466,11 @@
- product: ThreadX
- product: USBX
- product: Vert.x
+- reason: Elasticsearch
+ allOf:
+ - cna: elastic
+ - anyOf:
+ - product: Elasticsearch
- reason: Esri
allOf:
- cna: Esri
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c842100a0185e3f53206225209d61f2b17b396e3
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c842100a0185e3f53206225209d61f2b17b396e3
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits