openSUSE-SU-2021:1279-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:1279-1
openSUSE-SU-2021:1279-1
Summary: Security update for haserl
Details: This update for haserl fixes the following issues: Update to version 0.9.36: * Fixed: Its possible to issue a PUT request without a CONTENT-TYPE. Assume an octet-stream in that case. This is CVE-2021-29133 and boo#1187671 * Change the Prefix for variables to be the REQUEST_METHOD (PUT/DELETE/GET/POST) THIS IS A BREAKING CHANGE * Mitigations vs running haserl to get access to files not available to the user.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/JVYZKN3OCXW2QGY6YJEPECSXP6JIERGL/, https://bugzilla.suse.com/1187671, https://www.suse.com/security/cve/CVE-2021-29133
Affected packages
Package
Name: haserl
Purl: pkg:rpm/suse/haserl&distro=SUSE%20Package%20Hub%2015%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
