ALAS2023-2025-1247


Amazon Linux 2023 Security Advisory: ALAS2023-2025-1247
Advisory Released Date: 2025-10-27
Advisory Updated Date: 2025-10-27
Severity: Important

Issue Overview:

gi-docgen does not encode search terms before inserting them into HTML, allowing XSS via a crafted URL. Description obtained from: https://gitlab.gnome.org/GNOME/gi-docgen/-/issues/228 (CVE-2025-11687)


Affected Packages:

gi-docgen


Issue Correction:
Run dnf update gi-docgen --releasever 2023.9.20251027 or dnf update --advisory ALAS2023-2025-1247 --releasever 2023.9.20251027 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
noarch:
    gi-docgen-fonts-2024.1-44.amzn2023.noarch
    gi-docgen-doc-2024.1-44.amzn2023.noarch
    gi-docgen-2024.1-44.amzn2023.noarch

src:
    gi-docgen-2024.1-44.amzn2023.src