Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

SUSE: 2022:0184-1 Critical Update: webkit2gtk3 Cross Site Scripting

suse
Calendar Grey January 25, 2022
Scroller Suse
A vital SUSE Security Patch addresses 53 vulnerabilities in webkit2gtk3, boosting performance and safeguarding security.
An update that fixes 53 vulnerabilities is now available

Summary

This update for webkit2gtk3 fixes the following issues: - Update to version 2.34.3 (bsc#1194019). - CVE-2021-30887: Fixed logic issue allowing unexpectedly unenforced Content Security Policy when processing maliciously crafted web content. - CVE-2021-30890: Fixed logic issue allowing universal cross site scripting when processing maliciously crafted web content. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-183=1 - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2022-183=1

References

#1194019

Cross- CVE-2018-8518 CVE-2018-8523 CVE-2019-8766

CVE-2019-8768 CVE-2019-8782 CVE-2019-8808

CVE-2019-8815 CVE-2020-10018 CVE-2020-13753

CVE-2020-27918 CVE-2020-29623 CVE-2020-3885

CVE-2020-3894 CVE-2020-3895 CVE-2020-3897

CVE-2020-3900 CVE-2020-3901 CVE-2020-3902

CVE-2020-9802 CVE-2020-9803 CVE-2020-9805

CVE-2020-9947 CVE-2020-9948 CVE-2020-9951

CVE-2020-9952 CVE-2021-1765 CVE-2021-1788

CVE-2021-1817 CVE-2021-1820 CVE-2021-1825

CVE-2021-1826 CVE-2021-1844 CVE-2021-1871

CVE-2021-30661 CVE-2021-30666 CVE-2021-30682

CVE-2021-30761 CVE-2021-30762 CVE-2021-30809

CVE-2021-30818 CVE-2021-30823 CVE-2021-30836

CVE-2021-30846 CVE-2021-30848 CVE-2021-30849

CVE-2021-30851 CVE-2021-30858 CVE-2021-...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0183-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.