RHSA-2025:1185: Moderate: doxygen security update
Doxygen can generate an online class browser (in HTML) and/or a reference manual (in LaTeX) from a set of documented source files. The documentation is extracted directly from the sources. Doxygen can also be configured to extract the code structure from undocumented source files. <br>Security Fix(es):<br><li> jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods (CVE-2020-11023)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:1185?
The severity of RHSA-2025:1185 is classified as moderate.
How do I fix RHSA-2025:1185?
To fix RHSA-2025:1185, upgrade the affected Doxygen packages to version 1.9.1-12.el9_2.
Which products are affected by RHSA-2025:1185?
RHSA-2025:1185 affects multiple Red Hat CodeReady Linux Builder products for various architectures including IBM z Systems, ARM 64, Power little endian, and x86_64.
Is there a workaround for RHSA-2025:1185?
There are no documented workarounds for RHSA-2025:1185, so updating the affected packages is recommended.
What components of Doxygen are impacted by RHSA-2025:1185?
The impacted components include the Doxygen package, Doxygen debuginfo, Doxygen debugsource, and Doxygen Doxywizard.