Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
330659ca by Salvatore Bonaccorso at 2026-09-17T16:03:06+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -70,55 +70,55 @@ CVE-2026-92783 (Yeti through 2.11.0 fails to validate 
caller permissions in the
 CVE-2026-92782 (Chroma through 1.5.9 fails to validate tenant and database 
segments wh ...)
        NOT-FOR-US: Chroma
 CVE-2026-92781 (Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 
contain a pro ...)
-       TODO: check
+       NOT-FOR-US: Builder.io Gen2 SDKs
 CVE-2026-92780 (KnowStreaming through 3.4.1 fails to enforce role-based access 
control ...)
-       TODO: check
+       NOT-FOR-US: KnowStreaming
 CVE-2026-92779 (Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 
contain a pro ...)
-       TODO: check
+       NOT-FOR-US: Builder.io Gen2 SDKs
 CVE-2026-92778 (CMAK through 3.0.0.6 fails to apply the scheduled leader 
election feat ...)
-       TODO: check
+       NOT-FOR-US: CMAK
 CVE-2026-92776 (Wiki.js through 2.5.314 fails to require path separators when 
matching ...)
-       TODO: check
+       NOT-FOR-US: Wiki.js
 CVE-2026-92775 (Wiki.js through 2.5.314 contains a server-side request forgery 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: Wiki.js
 CVE-2026-92774 (Wiki.js through 2.5.314 omits page tags from authorization 
checks in m ...)
-       TODO: check
+       NOT-FOR-US: Wiki.js
 CVE-2026-92773 (Trigger.dev before 4.6.0 fails to verify that an authenticated 
user co ...)
-       TODO: check
+       NOT-FOR-US: Trigger.dev
 CVE-2026-92772 (Leantime before 3.9.6 contains an authorization bypass 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: Leantime
 CVE-2026-92771 (Twenty before 2.35.0 fails to validate field and row 
permissions in th ...)
-       TODO: check
+       NOT-FOR-US: Twenty
 CVE-2026-92770 (Harbor through 2.15.2 fails to properly restrict the q query 
parameter ...)
-       TODO: check
+       NOT-FOR-US: Harbor
 CVE-2026-92765 (ArcherySec through 2.0.6 fails to validate organization 
ownership in t ...)
-       TODO: check
+       NOT-FOR-US: ArcherySec
 CVE-2026-92764 (OpenCVE before 3.1.0 fails to properly scope the organizations 
API end ...)
-       TODO: check
+       NOT-FOR-US: OpenCVE
 CVE-2026-92763 (Rundeck through 6.2.1 fails to properly authorize the 
importConfig and ...)
-       TODO: check
+       NOT-FOR-US: Rundeck
 CVE-2026-92762 (Pelican Panel versions before 1.0.0-beta35 enforce startup 
write permi ...)
-       TODO: check
+       NOT-FOR-US: Pelican Panel
 CVE-2026-92761 (WebVirtCloud fails to properly validate permission flags in 
UserInstan ...)
-       TODO: check
+       NOT-FOR-US: WebVirtCloud
 CVE-2026-92760 (Shlink through 5.1.6 fails to enforce API key role 
restrictions when i ...)
-       TODO: check
+       NOT-FOR-US: Shlink
 CVE-2026-92759 (SecObserve versions before 1.59.1 contain an information 
disclosure vu ...)
-       TODO: check
+       NOT-FOR-US: SecObserve
 CVE-2026-92754 (PatrowlManager through 1.8.4 contains an improper access 
control vulne ...)
-       TODO: check
+       NOT-FOR-US: PatrowlManager
 CVE-2026-92753 (PatrowlManager through 1.8.4 contains an authorization bypass 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: PatrowlManager
 CVE-2026-92752 (metasfresh DocumentAttachmentsRestController and 
CommentsRestControlle ...)
-       TODO: check
+       NOT-FOR-US: metasfresh
 CVE-2026-92751 (CMAK through 3.0.0.6 fails to install a cross-site request 
forgery fil ...)
-       TODO: check
+       NOT-FOR-US: CMAK
 CVE-2026-92750 (Harness through 3.3.0 omits access control validation in the 
infrastru ...)
-       TODO: check
+       NOT-FOR-US: Harness
 CVE-2026-92749 (SafeLine through 9.4.1 derives the management console 
session-signing  ...)
-       TODO: check
+       NOT-FOR-US: SafeLine
 CVE-2026-92748 (BC Security Empire before 6.7.1 fails to validate the 
multipart filena ...)
-       TODO: check
+       NOT-FOR-US: BC Security Empire
 CVE-2026-92599 (joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 
and >=18.0 ...)
        TODO: check
 CVE-2026-92598 (Nodemailer before 9.1.0 fails to apply UTS-46 normalization 
when encod ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/330659caaea8656e9358afd6b57f143a1d14e22b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/330659caaea8656e9358afd6b57f143a1d14e22b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to