https://bugzilla.redhat.com/show_bug.cgi?id=2094052
Bug ID: 2094052
Summary: CVE-2021-4231 angular: XSS vulnerability
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: low
Priority: low
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: aileenc(a)redhat.com, amctagga(a)redhat.com,
amurdaca(a)redhat.com, andrew.slice(a)redhat.com,
aoconnor(a)redhat.com, asm(a)redhat.com,
bniver(a)redhat.com, bodavis(a)redhat.com,
branto(a)redhat.com, chazlett(a)redhat.com,
danmick(a)gmail.com, david(a)gnsa.us, dbhole(a)redhat.com,
decathorpe(a)gmail.com, deparker(a)redhat.com,
dwd(a)fedoraproject.org, eduardo.ramalho(a)gmail.com,
epel-packagers-sig(a)lists.fedoraproject.org,
erack(a)redhat.com, fedora(a)zaniyah.org,
flucifre(a)redhat.com, fmuellner(a)redhat.com,
fzatlouk(a)redhat.com,
gecko-bugs-nobody(a)fedoraproject.org,
gmalinko(a)redhat.com, gmeno(a)redhat.com,
go-sig(a)lists.fedoraproject.org, i(a)stingr.net,
janstey(a)redhat.com, jcajka(a)cajka.dev,
jhorak(a)redhat.com, jochrist(a)redhat.com,
josef(a)toxicpanda.com, jwon(a)redhat.com,
kai-engert-fedora(a)kuix.de, kanderso(a)redhat.com,
kkeithle(a)redhat.com, klaas(a)demter.de,
klember(a)redhat.com, lemenkov(a)gmail.com,
loic(a)dachary.org, lvaleeva(a)redhat.com,
madam(a)redhat.com, mbenjamin(a)redhat.com,
mhackett(a)redhat.com, muagarwa(a)redhat.com,
ngompa13(a)gmail.com, ocs-bugs(a)redhat.com,
omajid(a)redhat.com, pdelbell(a)redhat.com,
pjasicek(a)redhat.com, polkit-devel(a)redhat.com,
ramkrsna(a)gmail.com, rhughes(a)redhat.com,
rstrode(a)redhat.com, rwagner(a)redhat.com,
sandmann(a)redhat.com, sostapov(a)redhat.com,
steve(a)silug.org, stransky(a)redhat.com,
thofmann(a)fedoraproject.org, tpopela(a)redhat.com,
trpost(a)rocketmail.com, vereddy(a)redhat.com,
zebob.m(a)gmail.com, zsvetlik(a)redhat.com
Blocks: 2094048
Target Milestone: ---
Classification: Other
A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been
classified as problematic. Affected is the handling of comments. The
manipulation leads to cross site scripting. It is possible to launch the attack
remotely but it might require an authentication first. Upgrading to version
11.0.5 and 11.1.0-next.3 is able to address this issue. The name of the patch
is ba8da742e3b243e8f43d4c63aa842b44e14f2b09. It is recommended to upgrade the
affected component.
References:
https://vuldb.com/?id.181356https://github.com/angular/angular/issues/40136https://security.snyk.io/vuln/SNYK-JS-ANGULARCORE-1070902https://github.com/angular/angular/commit/ba8da742e3b243e8f43d4c63aa842b44e…
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2094052
https://bugzilla.redhat.com/show_bug.cgi?id=2211910
Bug ID: 2211910
Summary: python-pyqt6-6.5.1 is available
Product: Fedora
Version: rawhide
Status: NEW
Component: python-pyqt6
Keywords: FutureFeature, Triaged
Assignee: thunderbirdtr(a)fedoraproject.org
Reporter: upstream-release-monitoring(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
jonathan(a)almalinux.org,
kde-sig(a)lists.fedoraproject.org, manisandro(a)gmail.com,
thunderbirdtr(a)fedoraproject.org
Target Milestone: ---
Classification: Fedora
Releases retrieved: 6.5.1
Upstream release that is considered latest: 6.5.1
Current version/release in rawhide: 6.5.0-2.fc39
URL: https://pypi.org/project/PyQt6/6.0.1
Please consult the package updates policy before you issue an update to a
stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/
More information about the service that created this bug can be found at:
https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_M…
Please keep in mind that with any upstream change, there may also be packaging
changes that need to be made. Specifically, please remember that it is your
responsibility to review the new version to ensure that the licensing is still
correct and that no non-free or legally problematic items have been added
upstream.
Based on the information from Anitya:
https://release-monitoring.org/project/149589/
To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/python-pyqt6
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2211910
https://bugzilla.redhat.com/show_bug.cgi?id=2212563
Bug ID: 2212563
Summary: CVE-2020-7677 yarnpkg: thenify: Arbitrary Code
Execution in thenify [epel-all]
Product: Fedora EPEL
Version: epel9
Status: NEW
Component: yarnpkg
Keywords: Security, SecurityTracking
Severity: high
Assignee: zsvetlik(a)redhat.com
Reporter: carl(a)redhat.com
CC: ahanwate(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
extras-qa(a)fedoraproject.org, manisandro(a)gmail.com,
ngompa13(a)gmail.com, zsvetlik(a)redhat.com
Depends On: 2127351
Blocks: 2127348 (CVE-2020-7677)
Target Milestone: ---
Classification: Fedora
+++ This bug was initially created as a clone of Bug #2127351 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one tracking bug has been filed, please correct all affected versions at
the same time. If you need to fix the versions independent of each other,
you may clone this bug as appropriate.
--- Additional comment from Avinash Hanwate on 2022-09-16 05:05:30 UTC ---
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
=====
# bugfix, security, enhancement, newpackage (required)
type=security
# low, medium, high, urgent (required)
severity=high
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=2127348,2127351
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users restart after update
suggest_reboot=False
======
Additionally, you may opt to use the bodhi web interface to submit updates:
https://bodhi.fedoraproject.org/updates/new
--- Additional comment from Fedora Update System on 2023-01-11 15:24:28 UTC ---
FEDORA-2023-ce8943223c has been submitted as an update to Fedora 37.
https://bodhi.fedoraproject.org/updates/FEDORA-2023-ce8943223c
--- Additional comment from Fedora Update System on 2023-01-11 15:24:34 UTC ---
FEDORA-2023-18fd476362 has been submitted as an update to Fedora 36.
https://bodhi.fedoraproject.org/updates/FEDORA-2023-18fd476362
--- Additional comment from Fedora Update System on 2023-01-12 02:41:56 UTC ---
FEDORA-2023-18fd476362 has been pushed to the Fedora 36 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh
--advisory=FEDORA-2023-18fd476362`
You can provide feedback for this update here:
https://bodhi.fedoraproject.org/updates/FEDORA-2023-18fd476362
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information
on how to test updates.
--- Additional comment from Fedora Update System on 2023-01-12 03:05:54 UTC ---
FEDORA-2023-ce8943223c has been pushed to the Fedora 37 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh
--advisory=FEDORA-2023-ce8943223c`
You can provide feedback for this update here:
https://bodhi.fedoraproject.org/updates/FEDORA-2023-ce8943223c
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information
on how to test updates.
--- Additional comment from Fedora Update System on 2023-01-21 03:30:39 UTC ---
FEDORA-2023-ce8943223c has been pushed to the Fedora 37 stable repository.
If problem still persists, please make note of it in this bug report.
--- Additional comment from Fedora Update System on 2023-01-21 03:40:45 UTC ---
FEDORA-2023-18fd476362 has been pushed to the Fedora 36 stable repository.
If problem still persists, please make note of it in this bug report.
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=2127348
[Bug 2127348] CVE-2020-7677 thenify: Arbitrary Code Execution in thenify
https://bugzilla.redhat.com/show_bug.cgi?id=2127351
[Bug 2127351] CVE-2020-7677 yarnpkg: thenify: Arbitrary Code Execution in
thenify [fedora-all]
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2212563
https://bugzilla.redhat.com/show_bug.cgi?id=2212561
Bug ID: 2212561
Summary: CVE-2022-3517 yarnpkg: nodejs-minimatch: ReDoS via the
braceExpand function [epel-all]
Product: Fedora EPEL
Version: epel9
Status: NEW
Component: yarnpkg
Keywords: Security, SecurityTracking
Severity: medium
Assignee: zsvetlik(a)redhat.com
Reporter: carl(a)redhat.com
CC: epel-packagers-sig(a)lists.fedoraproject.org,
extras-qa(a)fedoraproject.org, gsuckevi(a)redhat.com,
manisandro(a)gmail.com, ngompa13(a)gmail.com,
zsvetlik(a)redhat.com
Depends On: 2135472
Blocks: 2134609 (CVE-2022-3517,PRISMA-2022-0039)
Target Milestone: ---
Classification: Fedora
+++ This bug was initially created as a clone of Bug #2135472 +++
More information about this security flaw is available in the following bug:
http://bugzilla.redhat.com/show_bug.cgi?id=2134609
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--- Additional comment from Guilherme de Almeida Suckevicz on 2022-10-17
16:52:32 UTC ---
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
=====
# bugfix, security, enhancement, newpackage (required)
type=security
# low, medium, high, urgent (required)
severity=medium
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=2134609,2135472
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users restart after update
suggest_reboot=False
======
Additionally, you may opt to use the bodhi web interface to submit updates:
https://bodhi.fedoraproject.org/updates/new
--- Additional comment from Fedora Update System on 2023-01-11 15:24:31 UTC ---
FEDORA-2023-ce8943223c has been submitted as an update to Fedora 37.
https://bodhi.fedoraproject.org/updates/FEDORA-2023-ce8943223c
--- Additional comment from Fedora Update System on 2023-01-11 15:24:37 UTC ---
FEDORA-2023-18fd476362 has been submitted as an update to Fedora 36.
https://bodhi.fedoraproject.org/updates/FEDORA-2023-18fd476362
--- Additional comment from Fedora Update System on 2023-01-12 02:41:58 UTC ---
FEDORA-2023-18fd476362 has been pushed to the Fedora 36 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh
--advisory=FEDORA-2023-18fd476362`
You can provide feedback for this update here:
https://bodhi.fedoraproject.org/updates/FEDORA-2023-18fd476362
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information
on how to test updates.
--- Additional comment from Fedora Update System on 2023-01-12 03:05:57 UTC ---
FEDORA-2023-ce8943223c has been pushed to the Fedora 37 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh
--advisory=FEDORA-2023-ce8943223c`
You can provide feedback for this update here:
https://bodhi.fedoraproject.org/updates/FEDORA-2023-ce8943223c
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information
on how to test updates.
--- Additional comment from Fedora Update System on 2023-01-21 03:30:45 UTC ---
FEDORA-2023-ce8943223c has been pushed to the Fedora 37 stable repository.
If problem still persists, please make note of it in this bug report.
--- Additional comment from Fedora Update System on 2023-01-21 03:40:47 UTC ---
FEDORA-2023-18fd476362 has been pushed to the Fedora 36 stable repository.
If problem still persists, please make note of it in this bug report.
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=2134609
[Bug 2134609] CVE-2022-3517 nodejs-minimatch: ReDoS via the braceExpand
function
https://bugzilla.redhat.com/show_bug.cgi?id=2135472
[Bug 2135472] CVE-2022-3517 yarnpkg: nodejs-minimatch: ReDoS via the
braceExpand function [fedora-all]
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2212561