SUSE-SU-2023:2781-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2781-1
SUSE-SU-2023:2781-1
Summary: Security update for rmt-server
Details: This update for rmt-server fixes the following issues: Update to version 2.13: - CVE-2023-28120: Fixed a possible XSS Security Vulnerability in bytesliced strings for html_safe (bsc#1209507). - CVE-2023-27530: Fixed a DoS in multipart mime parsing (bsc#1209096). - CVE-2022-31254: Fixed escalation vector bug from user _rmt to root in the packaging file (bsc#1204285). Bug fixes: - Handle X-Original-URI header, partial fix for (bsc#1211398) - Force rmt-client-setup-res script to use https (bsc#1209825) - Mark secrets.yml.key file as part of the rpm to allow seamless downgrades (bsc#1207670) - Adding -f to the file move command when moving the mirrored directory to its final location (bsc#1203171) - Fix %post install of pubcloud subpackage reload of nginx (bsc#1206593) - Skip warnings regarding nokogiri libxml version mismatch (bsc#1202053) - Add option to turn off system token support (bsc#1205089) - Do not retry to import non-existing files in air-gapped mode (bsc#1204769)
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232781-1/, https://bugzilla.suse.com/1202053, https://bugzilla.suse.com/1203171, https://bugzilla.suse.com/1204285, https://bugzilla.suse.com/1204769, https://bugzilla.suse.com/1205089, https://bugzilla.suse.com/1206593, https://bugzilla.suse.com/1207670, https://bugzilla.suse.com/1209096, https://bugzilla.suse.com/1209507, https://bugzilla.suse.com/1209825, https://bugzilla.suse.com/1211398, https://www.suse.com/security/cve/CVE-2022-31254, https://www.suse.com/security/cve/CVE-2023-27530, https://www.suse.com/security/cve/CVE-2023-28120
Affected packages
Package
Name: rmt-server
Purl: pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
