Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#78302 - [element-web,element-desktop] 1.11.26-1: CVE-2023-30609
Attached to Project:
Community Packages
Opened by Pascal Ernster (hardfalcon) - Tuesday, 25 April 2023, 13:22 GMT
Last edited by T.J. Townsend (blakkheim) - Tuesday, 02 May 2023, 21:15 GMT
Opened by Pascal Ernster (hardfalcon) - Tuesday, 25 April 2023, 13:22 GMT
Last edited by T.J. Townsend (blakkheim) - Tuesday, 02 May 2023, 21:15 GMT
|
Detailselement-web and element-desktop 1.11.30 have been released and contain a fix for CVE-2023-30609, which is considered a "moderate" severity vulnerability with a CVSS score of 5.4/10:
https://github.com/matrix-org/matrix-react-sdk/security/advisories/GHSA-xv83-x443-7rmw https://github.com/vector-im/element-web/releases/tag/v1.11.30 https://github.com/vector-im/element-desktop/releases/tag/v1.11.30 |
This task depends upon
Comment by T.J. Townsend (blakkheim) -
Tuesday, 02 May 2023, 20:08 GMT
1.11.30 is now in [community-testing] so please let me know if it works ok for you.