Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE 15.5: SUSE-SU-2024:0077-1 Moderate: hawk2 XSS Patch

opensuse
Calendar Grey January 10, 2024
Dist Opensuse Esm H88
This new release for eagle4 tackles security concerns such as XSS weaknesses and enhancements to Secure flag settings. Discover additional details!
This update for hawk2 fixes the following issues: Fixed HttpOnly secure flag by default (bsc#1216508)

Description

This update for hawk2 fixes the following issues:

* Fixed HttpOnly secure flag by default (bsc#1216508).

* Fixed CSRF in errors_controller.rb protection (bsc#1216571).

Update to version 2.6.4+git.1702030539.5fb7d91b:

* Fix mime type issue in MS windows (bsc#1215438)

* Parametrize CORS Access-Control-Allow-Origin header (bsc#1213454)

* Tests: upgrate tests for ruby3.2 (tumbleweed) (bsc#1215976)

* Upgrade for ruby3.2 (tumbleweed) (bsc#1215976)

* Forbid special symbols in the category (bsc#1206217)

* Fix the sass-rails version on ~5.0 (bsc#1208533)

* Don't delete the private key if the public key is missing (bsc#1207930)

* make-sle155-compatible.patch . No bsc, it's for backwards compatibility.

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2024-76=1

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2024-76=1

* SUSE Linux Enterprise High Availability Extension 15 SP1

zypper in -t patch SUSE-SLE-Product-HA-15-SP1-2024-76=1

* SUSE Linux Enterprise High Availability Extension 15 SP2

zypper in -t patch SUSE-SLE-Product-HA-15-SP2-2024-76=1

* SUSE Linux Enterprise High Availability Extension 15 SP3

zypper in -t patch SUSE-SLE-Product-HA-15-SP3-2024-76=1

* SUSE Linux Enterprise High Availability Extension 15 SP4

zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2024-76=1

* SUSE Linux Enterprise High Availability Extension 15 SP5

zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2024-76=1

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)

* hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* hawk2-debugsource-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* hawk2-debuginfo-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* hawk2-debugsource-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* hawk2-debuginfo-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* SUSE Linux Enterprise High Availability Extension 15 SP1 (aarch64 ppc64le

s390x x86_64)

* hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* hawk2-debugsource-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* hawk2-debuginfo-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* SUSE Linux Enterprise High Availability Extension 15 SP2 (aarch64 ppc64le

s390x x86_64)

* hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* hawk2-debugsource-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* hawk2-debuginfo-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1

* SUSE Linux...

Read the Full Advisory

References

* bsc#1206217

* bsc#1207930

* bsc#1208533

* bsc#1213454

* bsc#1215438

* bsc#1215976

* bsc#1216508

* bsc#1216571

## References:

* https://bugzilla.suse.com/show_bug.cgi?id=1206217

* https://bugzilla.suse.com/show_bug.cgi?id=1207930

* https://bugzilla.suse.com/show_bug.cgi?id=1208533

* https://bugzilla.suse.com/show_bug.cgi?id=1213454

* https://bugzilla.suse.com/show_bug.cgi?id=1215438

* https://bugzilla.suse.com/show_bug.cgi?id=1215976

* https://bugzilla.suse.com/show_bug.cgi?id=1216508

* https://bugzilla.suse.com/show_bug.cgi?id=1216571

Announcement ID: SUSE-SU-2024:0076-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here