openSUSE Security Update: Security update for moinmoin-wiki
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2020:1966-1
Rating:             important
References:         #1178744 #1178745 
Cross-References:   CVE-2020-15275 CVE-2020-25074
Affected Products:
                    openSUSE Leap 15.2
______________________________________________________________________________

   An update that fixes two vulnerabilities is now available.

Description:

   This update for moinmoin-wiki fixes the following issues:

   - update to version 1.9.11: CVE-2020-25074 (boo#1178744): fix remote code
     execution via cache action CVE-2020-15275 (boo#1178745): fix malicious
     SVG attachment causing stored XSS vulnerability


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Leap 15.2:

      zypper in -t patch openSUSE-2020-1966=1



Package List:

   - openSUSE Leap 15.2 (noarch):

      moinmoin-wiki-1.9.11-lp152.3.3.1


References:

   https://www.suse.com/security/cve/CVE-2020-15275.html
   https://www.suse.com/security/cve/CVE-2020-25074.html
   https://bugzilla.suse.com/1178744
   https://bugzilla.suse.com/1178745
_______________________________________________
openSUSE Security Announce mailing list -- [email protected]
To unsubscribe, email [email protected]
List Netiquette: https://en.opensuse.org/openSUSE:Mailing_list_netiquette
List Archives: https://lists.opensuse.org/archives/list/[email protected]