Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ee327232 by Salvatore Bonaccorso at 2026-09-12T09:44:13+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -10,41 +10,41 @@ CVE-2026-90460 (An issue was discovered in OpenStack
Keystone before 29.0.3. Tok
NOTE: https://bugs.launchpad.net/keystone/+bug/2158931
NOTE: https://review.opendev.org/c/openstack/keystone/+/1002330
CVE-2026-90457 (The administrative password is hashed using a comparatively
weak, fast ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90456 (An example environment-configuration file for a bundled
inventory-mana ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90455 (A prior update that raised a bundled HTTP client library to a
version ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90454 (A deployment mode intended to expose only read access to a
bundled pac ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90453 (A file-upload handler redirects the authenticated client's
browser to ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90452 (Requests from the reverse proxy to the identity-provider
service for t ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90451 (An example environment-configuration file ships with a fixed,
publicly ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90450 (The application's role-authorization lookup defaults to
granting acces ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90449 (When a particular authentication mode is configured, the
reverse proxy ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90448 (A deployment mode intended to expose only read access to
stored data p ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90447 (A routing rule selects between two different authentication
mechanisms ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90446 (An application programming interface endpoint accepts a
user-supplied ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90445 (An interface that accepts file uploads from authenticated
users extrac ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90444 (A file-transfer interface that requires valid credentials
accepts atta ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-90443 (A web interface reflects a portion of the request URL into a
script co ...)
- TODO: check
+ NOT-FOR-US: CISA Malcolm
CVE-2026-89332 (Inclusion of functionality from an untrusted control sphere in
the Kir ...)
NOT-FOR-US: Amazon
CVE-2026-89268 (QloApps through 1.7.0 renders back-office list filter POST
parameters ...)
- TODO: check
+ NOT-FOR-US: QloApps
CVE-2026-89267 (starlette-admin versions 0.16.1 through 0.17.1 fail to enforce
the sea ...)
- TODO: check
+ NOT-FOR-US: Starlette-Admin
CVE-2026-89266 (stb_vorbis through 1.22 contains a heap buffer overflow in
start_decod ...)
TODO: check
CVE-2026-87919 (The Product XML Feed Manager for WooCommerce WordPress plugin
before ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ee327232f9bf07b47fdd53a376176a17a5a653bf
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ee327232f9bf07b47fdd53a376176a17a5a653bf
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits