Processing maliciously crafted web content may lead to unexpectedly unenforced Content Security Policy. (CVE-2021-30887) Processing maliciously crafted web content may lead to universal cross site scripting. (CVE-2021-30890) . MGASA-2021-0583 - Updated webkit2 packages fix security vulnerability Publication date: 23 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0583.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-30887, CVE-2021-30890 Processing maliciously crafted web content may lead to unexpectedly unenforced Content Security Policy. (CVE-2021-30887) Processing maliciously crafted web content may lead to universal cross site scripting. (CVE-2021-30890) References: - https://bugs.mageia.org/show_bug.cgi?id=29793 - https://webkitgtk.org/security/WSA-2021-0007.html - https://www.cve.org/CVERecord?id=CVE-2021-30887 - https://www.cve.org/CVERecord?id=CVE-2021-30890 SRPMS: - 8/core/webkit2-2.34.3-1.mga8 . Mageia released a crucial security patch fixing various vulnerabilities in web content management. Check the detailed release notes for full effects and remedies. Mageia Webkit2 Security Update, Cross Site Scripting Risks, Content Policy Fixes. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.