Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 34: FEDORA-2022-d7a4d7e7a4 Low: Plantuml Remote Code Execution

fedora
Calendar Grey April 26, 2022
Dist Fedora Esm H88
The latest patch for Fedora 35 rectifies the plantuml vulnerability related to stored XSS threats, enhancing the overall security posture of the system.
notes=Security fix for [CVE-2022-1231]

Summary

PlantUML is a program allowing to draw UML diagrams, using a simple

and human readable text description. It is extremely useful for code

documenting, sketching project architecture during team conversations

and so on.

PlantUML supports the following diagram types

- sequence diagram

- use case diagram

- class diagram

- activity diagram

- component diagram

- state diagram

notes=Security fix for [CVE-2022-1231]

* Mon Mar 7 2022 Sandipan Roy - 1:1.2022.2-1

- Updated version to 1.2022.2

* Sat Feb 5 2022 Jiri Vanek - 1:1.2021.16-3

- Rebuilt for java-17-openjdk as system jdk

* Fri Jan 21 2022 Fedora Release Engineering - 1:1.2021.16-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild

* Wed Dec 29 2021 Sandipan Roy - 1:1.2021.16-1

- Updated version to 1.2021.16

[ 1 ] Bug #2076163 - CVE-2022-1231 plantuml: Stored XSS in the context of the diagram embedder [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2076163

su -c 'dnf upgrade --advisory FEDORA-2022-e8b1324ec8' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 35
Version: 1.2022.2
Release: 1.fc35
Summary: Program to generate UML diagram from a text description

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here