Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Fedora 41: workrave 2025-d611c8d114 critical: xss autoescape exploit

fedora
Calendar Grey April 17, 2025
Dist Fedora Esm H88
Ubuntu 23.10 maintainer patch addresses privilege escalation vulnerability, crucial for system security.
Unretireing the package.

Summary

Workrave is a program that assists in the recovery and prevention of

Repetitive Strain Injury (RSI). The program frequently alerts you to

take micro-pauses, rest breaks and restricts you to your daily limit.

Update Information:

Unretireing the package.

Change Log

* Tue Apr 8 2025 Łukasz Wojniłowicz - 1.11.0~rc.1-1 - Unretirement import (fedora#2351398).

References


[ 1 ] Bug #2322802 - GNOME applet incompatible with GNOME 47 https://bugzilla.redhat.com/show_bug.cgi?id=2322802 [ 2 ] Bug #2328917 - CVE-2023-2142 workrave: Nunjucks autoescape bypass leads to cross site scripting [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2328917 [ 3 ] Bug #2328918 - CVE-2023-2142 workrave: Nunjucks autoescape bypass leads to cross site scripting [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2328918 [ 4 ] Bug #2351398 - Review Request: workrave - Program that assists in the recovery and prevention of RSI https://bugzilla.redhat.com/show_bug.cgi?id=2351398 [ 5 ] Bug #2358210 - F42FailsToInstall: workrave https://bugzilla.redhat.com/show_bug.cgi?id=2358210

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d611c8d114' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: workrave
Product: Fedora 41
Version: 1.11.0~rc.1
Release: 1.fc41
Summary: Program that assists in the recovery and prevention of RSI

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here