Описание
Security update for python-gi-docgen
This update for python-gi-docgen fixes the following issues:
- CVE-2025-11687: Fixed reflected DOM XSS (bsc#1251961)
Список пакетов
openSUSE Leap 16.0
python3-gi-docgen-2025.5-160000.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1251961
- SUSE CVE CVE-2025-11687 page
Описание
A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page - enabling DOM access, session cookie theft and other client-side attacks - via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).
Затронутые продукты
openSUSE Leap 16.0:python3-gi-docgen-2025.5-160000.1.1
Ссылки
- CVE-2025-11687
- SUSE Bug 1251961