Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
86bad094 by Salvatore Bonaccorso at 2026-08-11T22:31:50+02:00
Associate some CVEs with koha, itp'ed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6812,7 +6812,7 @@ CVE-2026-71291 (Bolt CMS renders content field values 
through Twig's full applic
 CVE-2026-71289 (The NASA-AMMOS Asynchronous Network Management System (ANMS) 
reference ...)
        NOT-FOR-US: NASA-AMMOS
 CVE-2026-71288 (Koha's guided report builder (reports/guided_reports.pl) reads 
the CGI ...)
-       NOT-FOR-US: Koha Library Management System
+       - koha <itp> (bug #702134)
 CVE-2026-71287 (Cacti's sanitize_sql_column (lib/functions.php) sanitizes 
user-supplie ...)
        - cacti <undetermined>
        TODO: check, assigned from "Turan Security" CNA without further 
detailed references
@@ -7724,15 +7724,15 @@ CVE-2026-70471 (Flowise is a drag-and-drop user 
interface for building customize
 CVE-2026-70470 (Flowise is a drag & drop user interface to build a customized 
large la ...)
        NOT-FOR-US: Flowise
 CVE-2026-70373 (Koha's reports/issues_stats.pl (the circulation statistics 
report) bui ...)
-       NOT-FOR-US: Koha Library Management System
+       - koha <itp> (bug #702134)
 CVE-2026-70372 (Koha's reports/bor_issues_top.pl builds dynamic SQL in sub 
calculate b ...)
-       NOT-FOR-US: Koha Library Management System
+       - koha <itp> (bug #702134)
 CVE-2026-70371 (Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub 
calculate ...)
-       NOT-FOR-US: Koha Library Management System
+       - koha <itp> (bug #702134)
 CVE-2026-70370 (Koha's reports/catalogue_stats.pl builds dynamic SQL in sub 
calculate  ...)
-       NOT-FOR-US: Koha Library Management System
+       - koha <itp> (bug #702134)
 CVE-2026-70369 (Koha's reports/acquisitions_stats.pl builds its per-cell 
statistics qu ...)
-       NOT-FOR-US: Koha Library Management System
+       - koha <itp> (bug #702134)
 CVE-2026-70368 (A stack-based out-of-bounds read vulnerability exists in the 
"s_vlog"  ...)
        - stunnel 3:5.80-1
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462029
@@ -40295,11 +40295,11 @@ CVE-2026-52780 (OpenProject is open-source, web-based 
project management softwar
 CVE-2026-52779 (OpenProject is open-source, web-based project management 
software. Pri ...)
        NOT-FOR-US: OpenProject
 CVE-2026-50767 (A stored cross-site scripting (XSS) vulnerability in the item 
type adm ...)
-       NOT-FOR-US: Koha Library Management System
+       - koha <itp> (bug #702134)
 CVE-2026-50766 (A stored cross-site scripting (XSS) vulnerability in the OPAC 
item det ...)
-       NOT-FOR-US: Koha Library Management System
+       - koha <itp> (bug #702134)
 CVE-2026-50765 (A stored cross-site scripting (XSS) vulnerability in the 
patron restri ...)
-       NOT-FOR-US: Koha Library Management System
+       - koha <itp> (bug #702134)
 CVE-2026-50137 (Budibase is an open-source low-code platform. Prior to 3.39.0, 
an anon ...)
        NOT-FOR-US: Budibase
 CVE-2026-50136 (Budibase is an open-source low-code platform. Prior to 3.39.3, 
the app ...)
@@ -197018,7 +197018,7 @@ CVE-2025-52447 (Authorization Bypass Through 
User-Controlled Key vulnerability i
 CVE-2025-52446 (Authorization Bypass Through User-Controlled Key vulnerability 
in Sale ...)
        NOT-FOR-US: Salesforce
 CVE-2025-52360 (A Cross-Site Scripting (XSS) vulnerability exists in the OPAC 
search f ...)
-       NOT-FOR-US: Koha Library Management System
+       - koha <itp> (bug #702134)
 CVE-2025-51411 (A reflected cross-site scripting (XSS) vulnerability exists in 
Institu ...)
        NOT-FOR-US: Institute-of-Current-Students
 CVE-2025-46199 (Cross Site Scripting vulnerability in grav v.1.7.48 and before 
allows  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86bad094fc6573ad07b461979fc0448f4d1fd88b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86bad094fc6573ad07b461979fc0448f4d1fd88b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to