FlawAtlas
Search the atlas
SUSE-SU-2023:2280-1 Not scored

Security update for rmt-server

This update for rmt-server fixes the following issues: Updated to version 2.13: - CVE-2023-28120: Fixed a potential XSS issue in an embedded dependency (bsc#1209507). - CVE-2023-27530: Fixed a denial of service issue in multipart request parsing (bsc#1209096). Non-security fixes: - Fixed transactional update on GCE (bsc#1211398). - Use HTTPS in rmt-client-setup-res (bsc#1209825). - Various build fixes (bsc#1207670, bsc#1203171, bsc#1206593, bsc#1202053).

Exploit probability Not scored
Published May 24, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7.1 rmt-server
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS rmt-server
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS rmt-server
SUSE:Linux Enterprise Module for Public Cloud 15 SP3 rmt-server
SUSE:Linux Enterprise Real Time 15 SP3 rmt-server
SUSE:Linux Enterprise Server 15 SP3-LTSS rmt-server
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 rmt-server
SUSE:Manager Proxy 4.2 rmt-server
SUSE:Manager Server 4.2 rmt-server

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:2280-1

This update for rmt-server fixes the following issues: Updated to version 2.13: - CVE-2023-28120: Fixed a potential XSS issue in an embedded dependency (bsc#1209507). - CVE-2023-27530: Fixed a denial of service issue in multipart request parsing (bsc#1209096). Non-security fixes: - Fixed transactional update on GCE (bsc#1211398). - Use HTTPS in rmt-client-setup-res (bsc#1209825). - Various build fixes (bsc#1207670, bsc#1203171, bsc#1206593, bsc#1202053).

View original source

05 / REFERENCES

Further evidence