Amazon Linux 2023 Security Advisory: ALAS2023-2025-1247
Advisory Released Date: 2025-10-27
Advisory Updated Date: 2025-10-27
Severity:
Important
Issue Overview:
gi-docgen does not encode search terms before inserting them into HTML, allowing XSS via a crafted URL. Description obtained from: https://gitlab.gnome.org/GNOME/gi-docgen/-/issues/228 (CVE-2025-11687)
Affected Packages:
gi-docgen
Issue Correction:
Run dnf update gi-docgen --releasever 2023.9.20251027 or dnf update --advisory ALAS2023-2025-1247 --releasever 2023.9.20251027 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
New Packages:
noarch:
gi-docgen-fonts-2024.1-44.amzn2023.noarch
gi-docgen-doc-2024.1-44.amzn2023.noarch
gi-docgen-2024.1-44.amzn2023.noarch
src:
gi-docgen-2024.1-44.amzn2023.src