{"schema_version":"1.7.3","id":"SUSE-SU-2023:2781-1","published":"2023-07-04T11:09:54Z","modified":"2026-02-04T04:30:12.534159Z","related":["CVE-2022-31254","CVE-2023-27530","CVE-2023-28120"],"upstream":["CVE-2022-31254","CVE-2023-27530","CVE-2023-28120"],"summary":"Security update for rmt-server","details":"This update for rmt-server fixes the following issues:\n\nUpdate to version 2.13:\n\n- CVE-2023-28120: Fixed a possible XSS Security Vulnerability in bytesliced strings for html_safe (bsc#1209507).\n- CVE-2023-27530: Fixed a DoS in multipart mime parsing (bsc#1209096).\n- CVE-2022-31254: Fixed escalation vector bug from user _rmt to root in the packaging file (bsc#1204285).\n\nBug fixes:\n\n- Handle X-Original-URI header, partial fix for (bsc#1211398)\n- Force rmt-client-setup-res script to use https (bsc#1209825)\n- Mark secrets.yml.key file as part of the rpm to allow seamless downgrades (bsc#1207670)\n- Adding -f to the file move command when moving the mirrored directory to its final location (bsc#1203171) \n- Fix %post install of pubcloud subpackage reload of nginx (bsc#1206593)\n- Skip warnings regarding nokogiri libxml version mismatch (bsc#1202053)\n- Add option to turn off system token support (bsc#1205089)\n- Do not retry to import non-existing files in air-gapped mode (bsc#1204769)\n","affected":[{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP5","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.13-150500.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server-pubcloud":"2.13-150500.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2781-1.json"}},{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP5","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.13-150500.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server":"2.13-150500.3.3.1","rmt-server-config":"2.13-150500.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2781-1.json"}},{"package":{"name":"rmt-server","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/rmt-server&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.13-150500.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server":"2.13-150500.3.3.1","rmt-server-config":"2.13-150500.3.3.1","rmt-server-pubcloud":"2.13-150500.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2781-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20232781-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203171"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204285"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204769"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205089"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206593"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207670"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209096"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209507"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209825"},{"type":"REPORT","url":"https://bugzilla.suse.com/1211398"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-31254"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-27530"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28120"}]}