Security update for rmt-server
This update for rmt-server fixes the following issues: Update to version 2.13: - CVE-2023-28120: Fixed a possible XSS Security Vulnerability in bytesliced strings for html_safe (bsc#1209507). - CVE-2023-27530: Fixed a DoS in multipart mime parsing (bsc#1209096). - CVE-2022-31254: Fixed escalation vector bug from user _rmt to root in the packaging file (bsc#1204285). Bug fixes: - Handle X-Original-URI header, partial fix for (bsc#1211398) - Force rmt-client-setup-res script to use https (bsc#1209825) - Mark secrets.yml.key file as part of the rpm to allow seamless downgrades (bsc#1207670) - Adding -f to the file move command when moving the mirrored directory to its final location (bsc#1203171) - Fix %post install of pubcloud subpackage reload of nginx (bsc#1206593) - Skip warnings regarding nokogiri libxml version mismatch (bsc#1202053) - Add option to turn off system token support (bsc#1205089) - Do not retry to import non-existing files in air-gapped mode (bsc#1204769)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for rmt-server fixes the following issues: Update to version 2.13: - CVE-2023-28120: Fixed a possible XSS Security Vulnerability in bytesliced strings for html_safe (bsc#1209507). - CVE-2023-27530: Fixed a DoS in multipart mime parsing (bsc#1209096). - CVE-2022-31254: Fixed escalation vector bug from user _rmt to root in the packaging file (bsc#1204285). Bug fixes: - Handle X-Original-URI header, partial fix for (bsc#1211398) - Force rmt-client-setup-res script to use https (bsc#1209825) - Mark secrets.yml.key file as part of the rpm to allow seamless downgrades (bsc#1207670) - Adding -f to the file move command when moving the mirrored directory to its final location (bsc#1203171) - Fix %post install of pubcloud subpackage reload of nginx (bsc#1206593) - Skip warnings regarding nokogiri libxml version mismatch (bsc#1202053) - Add option to turn off system token support (bsc#1205089) - Do not retry to import non-existing files in air-gapped mode (bsc#1204769)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1202053
- https://bugzilla.suse.com/1203171
- https://bugzilla.suse.com/1204285
- https://bugzilla.suse.com/1204769
- https://bugzilla.suse.com/1205089
- https://bugzilla.suse.com/1206593
- https://bugzilla.suse.com/1207670
- https://bugzilla.suse.com/1209096
- https://bugzilla.suse.com/1209507
- https://bugzilla.suse.com/1209825
- https://bugzilla.suse.com/1211398
- https://www.suse.com/security/cve/CVE-2022-31254
- https://www.suse.com/security/cve/CVE-2023-27530
- https://www.suse.com/security/cve/CVE-2023-28120
- https://www.suse.com/support/update/announcement/2023/suse-su-20232781-1/