Upstream announcements: WordPress 6.9.2 Release WordPress 6.9.3 and 7.0 beta 4 WordPress 6.9.4 Release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bf984d4931 2026-03-21 00:15:22.234290+00:00 -------------------------------------------------------------------------------- Name : wordpress Product : Fedora 44 Version : 6.9.4 Release : 1.fc44 URL : https://wordpress.org/ Summary : Blog tool and publishing platform Description : Wordpress is an online publishing / weblog package that makes it very easy, almost trivial, to get information out to people on the web. Important information in /usr/share/doc/wordpress/README.fedora -------------------------------------------------------------------------------- Update Information: Upstream announcements: WordPress 6.9.2 Release WordPress 6.9.3 and 7.0 beta 4 WordPress 6.9.4 Release -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 12 2026 Remi Collet - 6.9.4-1 - WordPress 6.9.4 Release * Wed Mar 11 2026 Remi Collet - 6.9.3-1 - WordPress 6.9.3 Release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2446481 - CVE-2026-3906 wordpress: WordPress: Unauthorized access to post notes via improper REST API permission check [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2446481 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bf984d4931' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Single Sign-On 7.4.4 security update Advisory ID: RHSA-2020:5533-01 Product: Red Hat Single Sign-On Advisory URL: https://access.redhat.com/errata/RHSA-2020:5533 Issue date: 2020-12-15 CVE Names: CVE-2020-10695 CVE-2020-13822 CVE-2020-25638 CVE-2020-25649 CVE-2020-27826 ==================================================================== 1. Summary: A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Single Sign-On 7.4 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. This release of Red Hat Single Sign-On 7.4.4 serves as a replacement for Red Hat Single Sign-On 7.4.3, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix(es): * redhat-sso-7-openshift-containers: /etc/passwd is given incorrect privileges (CVE-2020-10695) * hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used (CVE-2020-25638) * jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) (CVE-2020-25649) * keycloak:Account REST API can update user metadata attributes (CVE-2020-27826) * keycloak-nodejs-connect: nodejs-elliptic: improper encoding checks allows a certain degree of signature malleability in ECDSA signatures (CVE-2020-13822) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). 4. Bugs fixed (https://bugzilla.redhat.com/): 1817530 - CVE-2020-10695 containers/redhat-sso-7: /etc/passwd is given incorrect privileges 1848647 - CVE-2020-13822 nodejs-elliptic: improper encoding checks allows a certain degree of signature malleability in ECDSA signatures 1881353 - CVE-2020-25638 hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used 1887664 - CVE-2020-25649 jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) 1905089 - CVE-2020-27826 keycloak: Account REST API can update user metadata attributes 5. References: https://access.redhat.com/security/cve/CVE-2020-10695 https://access.redhat.com/security/cve/CVE-2020-13822 https://access.redhat.com/security/cve/CVE-2020-25638 https://access.redhat.com/security/cve/CVE-2020-25649 https://access.redhat.com/security/cve/CVE-2020-27826 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX9jwk9zjgjWX9erEAQhoww//RJf6hmlOG+SytK34kfkqWJtMxIZSN4Dg ePIvMRY1OD7zH7EF9MK9l6uXNd9vRg46EH3Pzlehd0c3EAMTPCkWEhb+iqG81TKy kFEwAoh506JuJKoSD4GynFaA9gP1UEWMPsOSrxGeak6ZFwb88EULoYzwj9Tb5Yin oW1lpCtAWrwMrM0yU1764xMzs+RoQcxesrDTYqllQ5PrFERZKwpAIJocdoLOXimt EezgfovyCIcz5Sq7eREapO4X/y+v5rYVOVtgZT/KiQIbVXwvMMPAp5PpA773Bl6t Pq74Blh4TF1MLYNnpL9w4JyGp7OcjEDN/UzonpD8BlScLl+kv2Jk/ujUaMrZAYKb K+/IexMzE+tVuOY2NveVTX9zTIkeOk0OJvnEj1hu0Mz+B+ThlxNPoSa/iqtqD5K5 8LBwEPLGRC46XxHYECkHcoqacrCCwa3uS8uf1EEncnyiHju6xY3twb4krpOdoNZj 3v+bgmubqT7lACj2skQtZSZ2QcSo22+Eld3topqD75gGmvwdGf+4y5wUZ+6mYttc nvsHXRmOvy60ydcvyIcWIa8wcLAv92K0KnkLD51HuypjO2j3UtChwiha6jkxSmwg g2zhmph3VxNycGmDJqIqVTR0HXntvnax1VgzdbsrniHcS+c68VBD4oq5rc00xP7m s8G1QLK7RvE=5J+9 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.