Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE 15 SP5: 2023:0126-1 Moderate: Syncthing XSS Fix

opensuse
Calendar Grey June 16, 2023
Dist Opensuse Esm H88
Follow these steps to deploy the Syncthing patch addressing the moderate severity XSS vulnerability and ensure your system's security during the process
An update that fixes one vulnerability is now available

Description

This update for syncthing fixes the following issues:

- Update to 1.13.5

* This release fixes CVE-2022-46165 “Cross-site Scripting (XSS) in Web

GUI”

* Bugfixes:

#8503: "syncthing cli config devices add" reflect error when using

--addresses flag #8764: Ignore patterns creating during folder addition

are not loaded #8778: Tests fail on Windows with Go 1.20 #8779: Test

cleanup fails all model tests on Windows on Go 1.20 #8859: Incorrect

handling of path for auto accepted folder

* Other issues:

#8799: "fatal error: checkptr: converted pointer straddles multiple

allocations" in crypto tests

- Update to 1.23.4

- Bugfixes:

#8851: "Running global migration to fix encryption file sizes" on

every start

- Update to 1.23.3

* Bugfixes:

#5408: Selection of time in versions GUI not possible without editing

the string inside the textfield #8277: Mutual encrypted sharing doesn't

work...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2023-126=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64):

syncthing-1.23.5-bp155.2.3.1

syncthing-relaysrv-1.23.5-bp155.2.3.1

References

https://www.suse.com/security/cve/CVE-2022-46165.html

https://bugzilla.suse.com/1212085

Announcement ID: openSUSE-SU-2023:0126-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here