Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
4bf0ffe8 by Salvatore Bonaccorso at 2026-07-17T14:58:59+02:00
Add two new jetty issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1330,7 +1330,11 @@ CVE-2026-8919 (Permissive Cross-domain Security Policy
with Untrusted Domains in
CVE-2026-8590 (Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server
modules ...)
NOT-FOR-US: Spotfire
CVE-2026-8384 (In Eclipse Jetty, an HTTP URI of this form:
/public;/../admin/sec ...)
- TODO: check
+ - jetty12 <unfixed>
+ - jetty9 <unfixed>
+ NOTE:
https://github.com/jetty/jetty.project/security/advisories/GHSA-w7x5-g22v-xqhr
+ NOTE: https://github.com/jetty/jetty.project/pull/14969
+ NOTE: Fixed by:
https://github.com/jetty/jetty.project/commit/82969c77f6da46e27008b10b3c14840cd31db084
(jetty-12.0.35)
CVE-2026-8314 (A security issue exists within Arena\xae Simulation due to a
memory co ...)
NOT-FOR-US: Rockwell Automation
CVE-2026-8313 (A security issue exists within Arena\xae Simulation due to a
memory co ...)
@@ -1344,7 +1348,9 @@ CVE-2026-7494 (Nexus Repository 3 is vulnerable to
Server-Side Request Forgery (
CVE-2026-6851 (An Improper link resolution before file access ('link
following') vuln ...)
NOT-FOR-US: Bitdefender
CVE-2026-6790 (In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there
is no ...)
- TODO: check
+ - jetty12 <unfixed>
+ - jetty9 <unfixed>
+ NOTE:
https://github.com/jetty/jetty.project/security/advisories/GHSA-7p3p-8qv8-m2vh
CVE-2026-62659 (A security flaw was discovered in the NETGEAR WAX333 Access
Point that ...)
NOT-FOR-US: Netgear
CVE-2026-62658 (A security flaw was discovered in certain NETGEAR Nighthawk
RAX series ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4bf0ffe8ecdc7ec29bfe989ed047a2c2fb737953
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4bf0ffe8ecdc7ec29bfe989ed047a2c2fb737953
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits