4.5.5. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-83ab16425f 2025-06-29 01:03:14.526427+00:00 -------------------------------------------------------------------------------- Name : moodle Product : Fedora 42 Version : 4.5.5 Release : 1.fc42 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. -------------------------------------------------------------------------------- Update Information: 4.5.5 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 19 2025 Gwyn Ciesla - 4.5.5-1 - 4.5.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373852 - CVE-2025-49518 moodle: IDOR allows fetching of recently accessed courses for other users via web service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373852 [ 2 ] Bug #2373856 - CVE-2025-49513 moodle: Password can be revealed in login page after log out due to caching [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373856 [ 3 ] Bug #2373859 - CVE-2025-49514 moodle: SSRF risk via DNS rebind [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373859 [ 4 ] Bug #2373861 - CVE-2025-49515 moodle: Course visibility not honoured consistently [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373861 [ 5 ] Bug #2373862 - CVE-2025-49516 moodle: CSRF risk in badges backpack management [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373862 [ 6 ] Bug #2373864 - CVE-2025-49517 moodle: Missing authorisation checks in BigBlueButton view page [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2373864 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-83ab16425f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Red Hat Ansible Tower 3.7.4-1 - RHEL7 Container 2. Description: * Fixed two jQuery vulnerabilities (CVE-2020-11022, CVE-2020-11023) * Improved Ansible Tower's web service configuration to allow for. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: security update - Red Hat Ansible Tower 3.7.4-1 - RHEL7 Container Advisory ID: RHSA-2020:5249-01 Product: Red Hat Ansible Tower Advisory URL: https://access.redhat.com/errata/RHSA-2020:5249 Issue date: 2020-11-30 CVE Names: CVE-2019-18874 CVE-2020-7676 CVE-2020-7720 CVE-2020-7743 CVE-2020-11022 CVE-2020-11023 ==================================================================== 1. Summary: Red Hat Ansible Tower 3.7.4-1 - RHEL7 Container 2. Description: * Fixed two jQuery vulnerabilities (CVE-2020-11022, CVE-2020-11023) * Improved Ansible Tower's web service configuration to allow for processing more simultaneous HTTP(s) requests by default * Updated several dependencies of Ansible Tower's User Interface to address (CVE-2020-7720, CVE-2020-7743, CVE-2020-7676) * Updated to the latest version of python-psutil to address CVE-2019-18874 * Added several optimizations to improve performance for a variety of high-load simultaneous job launch use cases * Fixed workflows to no longer prevent certain users from being able to edit approval nodes * Fixed confusing behavior for social auth logins across distinct browser tabs * Fixed launching of Job Templates that use prompt-at-launch Ansible Vault credentials 3. Solution: For information on upgrading Ansible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://legacy-controller-docs.ansible.com/ansible-tower/ index.html 4. Bugs fixed (https://bugzilla.redhat.com/): 1828406 - CVE-2020-11022 jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method 1850004 - CVE-2020-11023 jquery: Passing HTMLcontaining elements to manipulation methods could result in untrusted code execution 5. References: https://access.redhat.com/security/cve/CVE-2019-18874 https://access.redhat.com/security/cve/CVE-2020-7676 https://access.redhat.com/security/cve/CVE-2020-7720 https://access.redhat.com/security/cve/CVE-2020-7743 https://access.redhat.com/security/cve/CVE-2020-11022 https://access.redhat.com/security/cve/CVE-2020-11023 https://access.redhat.com/security/updates/classification#moderate 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX8T+OtzjgjWX9erEAQhfUA//as832FB6CfzebHnoVBMz8gro1sZQhTgH uzYWdgYkDI4kMqO8u4bD3k9YXaYwub32d5xcpkOZ9ZtTl263EmpA807E5qATCuli Tn5PmIJ80y9HbHfK0xmjd+bm7FJZZsFO0JEKkXbYeTxljgZRgIXN42fCZjn22j5m QzhA2YCU3v7y+CRplqftvXP7LpBZtoSvCHr/hWHXuAirvtO3epV8+YLoAtnzT0Xl kRJbsSC9INuYpCoMBR2owKUX5aklB6q9zWyzGpkbxMrqBEnAi9xm/Pmey/u9Lmzn h8kXzthVkolKw9RIp5Qnp95h9110gvVxwgIpU2a+n+JipONBgrOCARlj9ttOuxfZ erCOaDgAwHHHfK+qXOZtZJ36uX9DiWZCOaBkgFzSOLNqtoGO5YBloMQx3Ivt7IsE WQZ3rVttEklI06Vlm2q6Tyz6E78WUjr12Eh1S6QwN6Gjp9SVgYip1RCkBErulgt3 edIQfIewynXOP3rrmLbLy68IGnNz2xJgVzW84WtEY7mygISv7/O9u0a2Ar+2Jm++ rXlXeK5+Shl4h4MeY+4fvH2k5TaSCliMLK+lCl5H65H+DPLHg90mlkP8wu8XoGCI AKoU9hrPRxdCHijX2zH6NFZ75Kmzk//7SiCNIvgZAwDbiu/GK5/+xxcfpukE5Tld +uNGueVnork=BM3i -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Bump to the latest patch release of the openvas 8.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-63633ea21c 2016-09-22 20:29:44.068181 -------------------------------------------------------------------------------- Name : openvas-gsa Product : Fedora 23 Version : 6.0.11 Release : 3.fc23 URL : Summary : Greenbone Security Assistant (GSA) is GUI to the OpenVAS Description : The Greenbone Security Assistant (GSA) is a lean web service offering a user web interface for the Open Vulnerability Assessment System (OpenVAS). The GSA uses XSL transformation style-sheets that converts OMP responses from the OpenVAS infrastructure into presentable HTML. -------------------------------------------------------------------------------- Update Information: Bump to the latest patch release of the openvas 8.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1371726 - openvas-gsa-6.0.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=1371726 [ 2 ] Bug #1371732 - openvas-manager-6.0.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=1371732 [ 3 ] Bug #1371731 - openvas-libraries-8.0.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=1371731 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update openvas-gsa' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Bump to the latest patch release of the openvas 8.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-b9ab1def88 2016-09-22 20:29:50.114945 -------------------------------------------------------------------------------- Name : openvas-gsa Product : Fedora 24 Version : 6.0.11 Release : 3.fc24 URL : Summary : Greenbone Security Assistant (GSA) is GUI to the OpenVAS Description : The Greenbone Security Assistant (GSA) is a lean web service offering a user web interface for the Open Vulnerability Assessment System (OpenVAS). The GSA uses XSL transformation style-sheets that converts OMP responses from the OpenVAS infrastructure into presentable HTML. -------------------------------------------------------------------------------- Update Information: Bump to the latest patch release of the openvas 8.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1371726 - openvas-gsa-6.0.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=1371726 [ 2 ] Bug #1371732 - openvas-manager-6.0.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=1371732 [ 3 ] Bug #1371731 - openvas-libraries-8.0.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=1371731 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update openvas-gsa' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.