[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2023:2781-1 -- SLES rmt-server

ID: oval:org.secpod.oval:def:89049049Date: (C)2023-07-18   (M)2024-01-29
Class: PATCHFamily: unix




This update for rmt-server fixes the following issues: Update to version 2.13: * CVE-2023-28120: Fixed a possible XSS Security Vulnerability in bytesliced strings for html_safe . * CVE-2023-27530: Fixed a DoS in multipart mime parsing . * CVE-2022-31254: Fixed escalation vector bug from user _rmt to root in the packaging file . Bug fixes: * Handle X-Original-URI header, partial fix for * Force rmt-client-setup-res script to use https * Mark secrets.yml.key file as part of the rpm to allow seamless downgrades * Adding -f to the file move command when moving the mirrored directory to its final location * Fix %post install of pubcloud subpackage reload of nginx * Skip warnings regarding nokogiri libxml version mismatch * Add option to turn off system token support * Do not retry to import non-existing files in air-gapped mode

Platform:
SUSE Linux Enterprise Server 15 SP5
Product:
rmt-server
Reference:
SUSE-SU-2023:2781-1
CVE-2022-31254
CVE-2023-27530
CVE-2023-28120
CVE    3
CVE-2023-28120
CVE-2022-31254
CVE-2023-27530
CPE    1
cpe:/a:rmt:rmt-server

© SecPod Technologies