
Update to 2.4.0 to address CVE-2022-29217. https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24

Update to 2.4.0 to address CVE-2022-29217. https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24

Update to new upstream version.

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-26700

The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-26700
This month’s People of WordPress feature shares the story of Dee Teal, based in Australia.

Several security issues were fixed in CUPS.

An update for zlib is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An InfluxDB vulnerability allowed attackers to login as any known database user.

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
In the thirty-second episode of the WordPress Briefing, WordPress Executive Director Josepha Haden Chomphosy shares her open source reading list for that post-WordCamp Europe downtime. Have a question you’d like answered? You can submit them to [email protected], either written or as a voice recording. Credits Editor: Dustin Hartzler Logo: Beatriz Fialho Production: Santana Inniss and Chloé Bringmann Song: […]

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in HTTP request smuggling or MITM attacks.
In the May 2022 survey we received responses from 1,155,729,496 sites across 273,593,762 unique domains and 12,069,814 web-facing computers. This reflects a loss of 5.23 million sites but a gain of 1.63 million domains and 95,200 computers.
nginx gained the largest number of domains (+1.24 million) and also a hefty amount of web-facing computers (+21,500), further securing its lead in both metrics. The total number of domains powered by nginx is now 75.0 million (+1.68%) and its market share has increased to 27.4% (+0.29). In terms of web-facing computers, nginx now has a total of 4.60 million; and although its leading market share fell slightly to 38.1%, Apache’s fell slightly further, extending the gap between the two to 9.54 percentage points.
nginx also continues to lead with a 30.7% share of all sites, despite losing the largest amount this month (-6.57 million). Apache follows with a share of 23.0%, but also lost a large number of sites (-2.32 million). The largest gain in this metric was seen by Google, which added 2.96 million sites to its total and increased its market share to 4.14%. LiteSpeed made the second largest gain of 1.26 million sites, and stays slightly ahead of Google with a share of 4.35%.
Google and LiteSpeed also made the only significant gains in the active sites metric, with Google gaining 977,000 and LiteSpeed gaining 151,000. Google has a greater lead in this metric, with a market share of 9.49% versus LiteSpeed’s 4.60%.
Cloudflare is continuing to edge its way up towards the leaders in the top million websites. This month it gained an additional 1,822 sites and now accounts for more than 20% of the top million sites for the first time. Meanwhile, both Apache and nginx lost more than a thousand sites each in the top million, making it look ever more likely that Cloudflare could gain places by the end of the year. Apache, nginx and Cloudflare currently have top-million site shares of 22.8%, 21.7% and 20.0% respectively.
One surprise this month was that the largest computer growth was seen not by nginx, but by the awselb (Amazon Web Services Elastic Load Balancing) web server, which gained 26,200 computers to reach a total of 378,000. These computers are likely to form only a small fraction of the AWS infrastructure used by the 1.86 million sites that are served from these computers, as AWS ELB achieves fault tolerance and scalability by automatically distributing incoming application traffic across multiple targets, and can also spread traffic across multiple AWS Availability Zones.


| Developer | April 2022 | Percent | May 2022 | Percent | Change |
|---|---|---|---|---|---|
| nginx | 361,438,143 | 31.13% | 354,871,628 | 30.71% | -0.43 |
| Apache | 268,005,916 | 23.08% | 265,688,420 | 22.99% | -0.10 |
| OpenResty | 92,950,864 | 8.01% | 92,848,366 | 8.03% | 0.03 |
| Cloudflare | 63,701,232 | 5.49% | 64,369,545 | 5.57% | 0.08 |

A malicious source package could write files outside the unpack directory.

An update for the maven:3.5 module is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Extended Update Support, and Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact

An update for the postgresql:10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

FreeType could be made to crash if it opened a specially crafted file.

It was discovered that SPIP, a website engine for publishing, would allow a malicious user to perform cross-site scripting attacks. For the oldstable distribution (buster), this problem has been fixed

– Fixed missing popups in some scenarios on Wayland (https://bugzilla.mozilla.org/show_bug.cgi?id=1771104) —- – Updated to latest upstream (100.0.2) —- – Fixed crashes on Wayland during recovery from sleep.

– Update to 1.1.2. Fixes rhbz#2085287. – Mitigate CVE-2022-29162 / GHSA-f3fp- gc8g-vw66.

– Update to 1.1.2. Fixes rhbz#2085287. – Mitigate CVE-2022-29162 / GHSA-f3fp- gc8g-vw66.

Update to pcre2-10.40, see https://github.com/PCRE2Project/pcre2/blob/pcre2-10.40/NEWS for details.

Several security vulnerabilities have been discovered in smarty3, the compiling PHP template engine. Template authors are able to run restricted static php methods or even arbitrary PHP code by crafting a malicious math string or by choosing an invalid {block} or {include} file name. If a math string was passed

Peter Agten discovered that several modules for TCP syslog reception in rsyslog, a system and kernel logging daemon, have buffer overflow flaws when octet-counted framing is used, which could result in denial of service or potentially the execution of arbitrary code.

The 5.17.11 stable kernel update contains a number of important fixes across the tree.

The 5.17.11 stable kernel update contains a number of important fixes across the tree.

Security fix for CVE-2022-28327

The 5.17.11 stable kernel update contains a number of important fixes across the tree.

An update for thunderbird is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openvswitch2.13 is now available in Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openvswitch2.16 is now available in Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
50 queries. 9.25 mb Memory usage. 0.389 seconds.