UbuntuUpdates.org

Package "velocity-tools"

Name: velocity-tools

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • collection of useful tools for Velocity template engine
  • collection of useful tools for Velocity template engine - documentation

Latest version: 2.0-7ubuntu0.20.04.1
Release: focal (20.04)
Level: security
Repository: universe

Links



Other versions of "velocity-tools" in Focal

Repository Area Version
base universe 2.0-7
updates universe 2.0-7ubuntu0.20.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.0-7ubuntu0.20.04.1 2023-08-10 17:06:59 UTC

  velocity-tools (2.0-7ubuntu0.20.04.1) focal-security; urgency=medium

  * SECURITY UPDATE: XSS and Code Execution
    - debian/patches/CVE-2020-13959.patch: fixed an XSS in VelocityViewServlet
      module
    - CVE-2020-13959

 -- Amir Naseredini <email address hidden> Thu, 10 Aug 2023 10:06:02 +0100

CVE-2020-13959 The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attac



About   -   Send Feedback to @ubuntu_updates