Security update for rmt-server
This update for rmt-server fixes the following issues: Updated to version 2.13: - CVE-2023-28120: Fixed a potential XSS issue in an embedded dependency (bsc#1209507). - CVE-2023-27530: Fixed a denial of service issue in multipart request parsing (bsc#1209096). Non-security fixes: - Fixed transactional update on GCE (bsc#1211398). - Use HTTPS in rmt-client-setup-res (bsc#1209825). - Various build fixes (bsc#1207670, bsc#1203171, bsc#1206593, bsc#1202053).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for rmt-server fixes the following issues: Updated to version 2.13: - CVE-2023-28120: Fixed a potential XSS issue in an embedded dependency (bsc#1209507). - CVE-2023-27530: Fixed a denial of service issue in multipart request parsing (bsc#1209096). Non-security fixes: - Fixed transactional update on GCE (bsc#1211398). - Use HTTPS in rmt-client-setup-res (bsc#1209825). - Various build fixes (bsc#1207670, bsc#1203171, bsc#1206593, bsc#1202053).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1202053
- https://bugzilla.suse.com/1203171
- https://bugzilla.suse.com/1206593
- https://bugzilla.suse.com/1207670
- https://bugzilla.suse.com/1209096
- https://bugzilla.suse.com/1209507
- https://bugzilla.suse.com/1209825
- https://bugzilla.suse.com/1211398
- https://www.suse.com/security/cve/CVE-2023-27530
- https://www.suse.com/security/cve/CVE-2023-28120
- https://www.suse.com/support/update/announcement/2023/suse-su-20232280-1/