Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

openSUSE 15.3: 2021:3325-1 Moderate Update for Rabbitmq-server DoS and XSS

opensuse
Calendar Grey October 9, 2021
Dist Opensuse Esm H88
Three vulnerabilities in rabbitmq-server prompted a moderate security update for openSUSE 15.3 to enhance system security.
An update that solves three vulnerabilities and has one errata is now available

Description

This update for rabbitmq-server fixes the following issues:

- CVE-2021-32718: Fixed improper neutralization of script-related HTML

tags in a web page (basic XSS) in management UI (bsc#1187818).

- CVE-2021-32719: Fixed improper neutralization of script-related HTML

tags in a web page (basic XSS) in federation management plugin

(bsc#1187819).

- CVE-2021-22116: Fixed improper input validation may lead to DoS

(bsc#1186203).

- Use /run instead of /var/run in tmpfiles.d configuration (bsc#1185075).

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-3325=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

erlang-rabbitmq-client-3.8.11-3.3.3

rabbitmq-server-3.8.11-3.3.3

rabbitmq-server-plugins-3.8.11-3.3.3

References

https://www.suse.com/security/cve/CVE-2021-22116.html

https://www.suse.com/security/cve/CVE-2021-32718.html

https://www.suse.com/security/cve/CVE-2021-32719.html

https://bugzilla.suse.com/1185075

https://bugzilla.suse.com/1186203

https://bugzilla.suse.com/1187818

https://bugzilla.suse.com/1187819

Announcement ID: openSUSE-SU-2021:3325-1
Rating: moderate
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here