Label rejected dispositions as CNA REJECTED

This commit is contained in:
Classic298
2026-07-08 20:39:17 +02:00
parent 15df05f82b
commit 924395b239
+3 -3
View File
@@ -44,13 +44,13 @@ For a full overview, see the [Security Policy](../security-policy).
| CVE | Title | Vendor Disposition | Official Resolution | Published |
| :--- | :--- | :--- | :--- | :--- |
| [CVE-2025-15603](./cve-2025-15603) | Insufficiently Random Values in start_windows.bat | Rejected | <span className="badge badge--success">REJECTED</span> | 2026-03-09 |
| [CVE-2025-15603](./cve-2025-15603) | Insufficiently Random Values in start_windows.bat | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2026-03-09 |
| [CVE-2026-0765](./cve-2026-0765) | PIP install_frontmatter_requirements Command Injection | Rejected | In progress | 2026-01-23 |
| [CVE-2026-0766](./cve-2026-0766) | load_tool_module_by_id Code Injection | Rejected | In progress | 2026-01-23 |
| [CVE-2026-0767](./cve-2026-0767) | Cleartext Transmission of Credentials | Rejected | In progress | 2026-01-23 |
| [CVE-2025-63391](./cve-2025-63391) | Authentication Bypass in /api/config | Rejected | <span className="badge badge--success">REJECTED</span> | 2025-12-18 |
| [CVE-2025-63391](./cve-2025-63391) | Authentication Bypass in /api/config | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-12-18 |
| [CVE-2024-7040](./cve-2024-7040) | Cross-Admin Chat Access via user_id Parameter | Rejected | In progress | 2025-10-15 |
| [CVE-2025-29446](./cve-2025-29446) | SSRF in verify_connection | Rejected | <span className="badge badge--success">REJECTED</span> | 2025-04-21 |
| [CVE-2025-29446](./cve-2025-29446) | SSRF in verify_connection | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-04-21 |
| [CVE-2024-7033](./cve-2024-7033) | Path Traversal in Model Download | Rejected | In progress | 2025-03-20 |
| [CVE-2024-7034](./cve-2024-7034) | Path Traversal in Model Upload | Rejected | In progress | 2025-03-20 |
| [CVE-2024-7038](./cve-2024-7038) | Path Oracle in Embedding-Model Update | Rejected | In progress | 2024-10-09 |