Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 32: Eclipse-Webtools 3.18.0-4 Moderate: SSRF and Info Disclosure

fedora
Calendar Grey August 31, 2020
Dist Fedora Esm H88
This latest Fedora release introduces essential security patches for OpenJDK, addressing RCE and data exposure issues.
Updates to the latest upstream release of Eclipse

Summary

Eclipse Webtools. This contains sub-packages for different sub-projects

of Eclipse Webtools project, including Server Tools, SourceEditing Tools,

Webservices Tools, Java EE Tools, JSF Tools, and Dali (JPA) Tools.

Updates to the latest upstream release of Eclipse. See the upstream release

notes for details: https://eclipseide.org/release/noteworthy/ Also

contains security fixes for CVE-2019-17566 and CVE-2019-17638.

* Mon Jul 27 2020 Fedora Release Engineering - 3.18.0-4

- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild

* Thu Jul 16 2020 Mat Booth - 3.18.0-3

- Remove no longer needed dep on jdom and json-simple and add missing BRs

on xml deps

- Drop xsl and xpath features

- Always use java 1.8 for building due to use of CORBA

* Fri Jul 10 2020 Mat Booth - 3.18.0-2

- Drop javaee/webservices/jsf plugins

* Wed Jun 24 2020 Mat Booth - 3.18.0-1

- Update to latest upstream release

* Fri Jan 24 2020 Mat Booth - 3.15.0-4

- Drop JPA tooling and remove requirement on Datatools

* Mon Dec 9 2019 Mat Booth - 3.15.0-3

- Fix build against latest jetty version

* Mon Dec 9 2019 Mat Booth - 3.15.0-2

- Drop JSDT features

* Mon Sep 16 2019 Mat Booth - 3.15.0-1

- Update to latest upstream release

* Wed Jun 26 2019 Mat Booth - 3.14.0-3

- Build missing xinclude embedded jar

* Fri Jun 14 2019 Mat Booth - 3.14.0-2

- Avoid running out of heap on s390x

* Wed Jun 12 2019 Mat Booth - 3.14.0-1

- Update to latest upstream release

* Tue Jun 11 2019 Mat Booth - 3.13.0-2

- Avoid using jgit providers from tycho-extras

[ 1 ] Bug #1848617 - CVE-2019-17566 batik: SSRF via "xlink:href"

https://bugzilla.redhat.com/show_bug.cgi?id=1848617

[ 2 ] Bug #1864680 - CVE-2019-17638 jetty: double release of resource can lead to information disclosure

https://bugzilla.redhat.com/show_bug.cgi?id=1864680

su -c 'dnf upgrade --advisory FEDORA-2020-cf8ef2f333' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/keys

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 3.18.0
Release: 4.fc32
Summary: Eclipse Webtools Projects

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here