mirror of
https://git.yoctoproject.org/poky
synced 2026-09-29 07:36:20 +02:00
CVE-2025-11687:
A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the
context of the page — enabling DOM access, session cookie theft and other client-side attacks — via
a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).
Reference:
[https://nvd.nist.gov/vuln/detail/CVE-2025-11687]
Upstream patch:
[c53d2640bf]
(From OE-Core rev: 76c1f08fadad94098bd265d662eb5a0408c95efc)
Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
Signed-off-by: Jinfeng Wang <jinfeng.wang.cn@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
Signed-off-by: Paul Barker <paul@pbarker.dev>
25 lines
1.0 KiB
BlitzBasic
25 lines
1.0 KiB
BlitzBasic
SUMMARY = "Documentation tool for GObject-based libraries"
|
|
DESCRIPTION = "GI-DocGen is a document generator for GObject-based libraries. GObject is \
|
|
the base type system of the GNOME project. GI-Docgen reuses the \
|
|
introspection data generated by GObject-based libraries to generate the API \
|
|
reference of these libraries, as well as other ancillary documentation."
|
|
HOMEPAGE = "https://gnome.pages.gitlab.gnome.org/gi-docgen/"
|
|
|
|
LICENSE = "GPL-3.0-or-later & Apache-2.0"
|
|
LIC_FILES_CHKSUM = "file://gi-docgen.py;beginline=1;endline=5;md5=2dc0f1f01202478cfe813c0e7f80b326"
|
|
|
|
SRC_URI = "\
|
|
git://gitlab.gnome.org/GNOME/gi-docgen.git;protocol=https;branch=main \
|
|
file://CVE-2025-11687.patch \
|
|
"
|
|
|
|
SRCREV = "96f2e9b93e1d8a5338eb05b87fd879856ab7b3cc"
|
|
|
|
S = "${WORKDIR}/git"
|
|
|
|
inherit setuptools3
|
|
|
|
RDEPENDS:${PN} += "python3-asyncio python3-core python3-jinja2 python3-json python3-markdown python3-markupsafe python3-pygments python3-toml python3-typogrify python3-xml"
|
|
|
|
BBCLASSEXTEND = "native nativesdk"
|