Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
330659ca by Salvatore Bonaccorso at 2026-09-17T16:03:06+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -70,55 +70,55 @@ CVE-2026-92783 (Yeti through 2.11.0 fails to validate
caller permissions in the
CVE-2026-92782 (Chroma through 1.5.9 fails to validate tenant and database
segments wh ...)
NOT-FOR-US: Chroma
CVE-2026-92781 (Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13
contain a pro ...)
- TODO: check
+ NOT-FOR-US: Builder.io Gen2 SDKs
CVE-2026-92780 (KnowStreaming through 3.4.1 fails to enforce role-based access
control ...)
- TODO: check
+ NOT-FOR-US: KnowStreaming
CVE-2026-92779 (Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13
contain a pro ...)
- TODO: check
+ NOT-FOR-US: Builder.io Gen2 SDKs
CVE-2026-92778 (CMAK through 3.0.0.6 fails to apply the scheduled leader
election feat ...)
- TODO: check
+ NOT-FOR-US: CMAK
CVE-2026-92776 (Wiki.js through 2.5.314 fails to require path separators when
matching ...)
- TODO: check
+ NOT-FOR-US: Wiki.js
CVE-2026-92775 (Wiki.js through 2.5.314 contains a server-side request forgery
vulnera ...)
- TODO: check
+ NOT-FOR-US: Wiki.js
CVE-2026-92774 (Wiki.js through 2.5.314 omits page tags from authorization
checks in m ...)
- TODO: check
+ NOT-FOR-US: Wiki.js
CVE-2026-92773 (Trigger.dev before 4.6.0 fails to verify that an authenticated
user co ...)
- TODO: check
+ NOT-FOR-US: Trigger.dev
CVE-2026-92772 (Leantime before 3.9.6 contains an authorization bypass
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: Leantime
CVE-2026-92771 (Twenty before 2.35.0 fails to validate field and row
permissions in th ...)
- TODO: check
+ NOT-FOR-US: Twenty
CVE-2026-92770 (Harbor through 2.15.2 fails to properly restrict the q query
parameter ...)
- TODO: check
+ NOT-FOR-US: Harbor
CVE-2026-92765 (ArcherySec through 2.0.6 fails to validate organization
ownership in t ...)
- TODO: check
+ NOT-FOR-US: ArcherySec
CVE-2026-92764 (OpenCVE before 3.1.0 fails to properly scope the organizations
API end ...)
- TODO: check
+ NOT-FOR-US: OpenCVE
CVE-2026-92763 (Rundeck through 6.2.1 fails to properly authorize the
importConfig and ...)
- TODO: check
+ NOT-FOR-US: Rundeck
CVE-2026-92762 (Pelican Panel versions before 1.0.0-beta35 enforce startup
write permi ...)
- TODO: check
+ NOT-FOR-US: Pelican Panel
CVE-2026-92761 (WebVirtCloud fails to properly validate permission flags in
UserInstan ...)
- TODO: check
+ NOT-FOR-US: WebVirtCloud
CVE-2026-92760 (Shlink through 5.1.6 fails to enforce API key role
restrictions when i ...)
- TODO: check
+ NOT-FOR-US: Shlink
CVE-2026-92759 (SecObserve versions before 1.59.1 contain an information
disclosure vu ...)
- TODO: check
+ NOT-FOR-US: SecObserve
CVE-2026-92754 (PatrowlManager through 1.8.4 contains an improper access
control vulne ...)
- TODO: check
+ NOT-FOR-US: PatrowlManager
CVE-2026-92753 (PatrowlManager through 1.8.4 contains an authorization bypass
vulnerab ...)
- TODO: check
+ NOT-FOR-US: PatrowlManager
CVE-2026-92752 (metasfresh DocumentAttachmentsRestController and
CommentsRestControlle ...)
- TODO: check
+ NOT-FOR-US: metasfresh
CVE-2026-92751 (CMAK through 3.0.0.6 fails to install a cross-site request
forgery fil ...)
- TODO: check
+ NOT-FOR-US: CMAK
CVE-2026-92750 (Harness through 3.3.0 omits access control validation in the
infrastru ...)
- TODO: check
+ NOT-FOR-US: Harness
CVE-2026-92749 (SafeLine through 9.4.1 derives the management console
session-signing ...)
- TODO: check
+ NOT-FOR-US: SafeLine
CVE-2026-92748 (BC Security Empire before 6.7.1 fails to validate the
multipart filena ...)
- TODO: check
+ NOT-FOR-US: BC Security Empire
CVE-2026-92599 (joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7
and >=18.0 ...)
TODO: check
CVE-2026-92598 (Nodemailer before 9.1.0 fails to apply UTS-46 normalization
when encod ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/330659caaea8656e9358afd6b57f143a1d14e22b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/330659caaea8656e9358afd6b57f143a1d14e22b
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits