There are 2 open security issues in bullseye.
There are 2 open security issues in bookworm.
commit 179b84710eddbbc41b09abac5bc28df7beb53790
Author: Thomas Goirand <zigo@debian.org>
Date: Wed Aug 12 10:14:45 2026 +0200
* CVE-2026-76878 / OSSA-2026-036: Watcher webhook trigger endpoint does not
enforce oslo.policy authorization. Any authenticated user who learns a
Watcher audit webhook URL can POST to the webhook to trigger an
administrator-owned EVENT audit and its associated action plan, regardless
of the caller's project or role. The webhook endpoint has lacked policy
enforcement since its introduction in the Ussuri release. Applied upstream
patch: "Add policy enforcement to webhook trigger endpoint".
(Closes: #1144880)
Among the 5 debian patches available in version 16.0.0-5 of the package, we noticed the following issues: