INFSA-2025:1329: doxygen security update

Information about definition

Identificator: INFSA-2025:1329

Type: security

Release date: 2025-03-17 13:05:54 UTC

Information about package

Doxygen can generate an online class browser (in HTML) and/or a reference manual (in LaTeX) from a set of documented source files. The documentation is extracted directly from the sources. Doxygen can also be configured to extract the code structure from undocumented source files.

Vulnerabilities description

  • CVE-2020-11023

    In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 6.1 no information
Critical, important, moderate, low

Updated packages