{"schema_version":"1.7.3","id":"SUSE-SU-2023:2295-1","published":"2023-05-25T07:56:07Z","modified":"2026-02-04T03:19:45.898354Z","related":["CVE-2023-27530","CVE-2023-28120"],"upstream":["CVE-2023-27530","CVE-2023-28120"],"summary":"Security update for rmt-server","details":"This update for rmt-server fixes the following issues:\n\nUpdated to version 2.13:\n\n- CVE-2023-28120: Fixed a potential XSS issue in an embedded\n  dependency (bsc#1209507).\n- CVE-2023-27530: Fixed a denial of service issue in multipart request\n  parsing (bsc#1209096).\n\nNon-security fixes:\n\n- Fixed transactional update on GCE (bsc#1211398).\n- Use HTTPS in rmt-client-setup-res (bsc#1209825).\n- Various build fixes (bsc#1207670, bsc#1203171, bsc#1206593,\n  bsc#1202053).\n","affected":[{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP4","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.13-150400.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server-pubcloud":"2.13-150400.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2295-1.json"}},{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP4","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.13-150400.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server":"2.13-150400.3.12.1","rmt-server-config":"2.13-150400.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2295-1.json"}},{"package":{"name":"rmt-server","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/rmt-server&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.13-150400.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server":"2.13-150400.3.12.1","rmt-server-config":"2.13-150400.3.12.1","rmt-server-pubcloud":"2.13-150400.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2295-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20232295-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203171"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206593"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207670"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209096"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209507"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209825"},{"type":"REPORT","url":"https://bugzilla.suse.com/1211398"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-27530"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28120"}]}