An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for portus ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:2655-1 Rating: important References: #1059664 Cross-References: CVE-2017-14621 Affected Products: SUSE Linux Enterprise Module for Containers 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for portus fixes the following issues: - CVE-2017-14621: Fixed a XSS attack via the Team field, related to typeahead. (bsc#1059664) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Containers 12: zypper in -t patch SUSE-SLE-Module-Containers-12-2017-1642=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Module for Containers 12 (x86_64): portus-2.2.0-20.3.1 portus-debuginfo-2.2.0-20.3.1 portus-debugsource-2.2.0-20.3.1 References: https://www.suse.com/security/cve/CVE-2017-14621.html https://bugzilla.suse.com/1059664 . SUSE has released a security patch for Portus to remediate a severe XSS vulnerability. Ensure you apply the updates promptly to protect your infrastructure.. SUSE Security, Portus Update, XSS Threat, Threat Mitigation, Patch Instructions. . Severity: Important. LinuxSecurity.com Team
An update that fixes 10 vulnerabilities is now available. An update that fixes 10 vulnerabilities is now available. An update that fixes 10 vulnerabilities is now available.. SUSE Security Update: Security update for portus ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:1146-1 Rating: important References: #963326 #963327 #963328 #963563 #963604 #963608 #963617 #963625 #963627 #969943 Cross-References: CVE-2015-7576 CVE-2015-7577 CVE-2015-7578 CVE-2015-7579 CVE-2015-7580 CVE-2015-7581 CVE-2016-0751 CVE-2016-0752 CVE-2016-0753 CVE-2016-2098 Affected Products: SUSE Linux Enterprise Module for Containers 12 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. Description: Portus was updated to version 2.0.3, which brings several fixes and enhancements: - Fixed crono job when a repository could not be found. - Fixed compatibility issues with Docker 1.10 and Distribution 2.3. - Handle multiple scopes in token requests. - Add optional fields to token response. - Fixed notification events for Distribution v2.3. - Paginate through the catalog properly. - Do not remove all the repositories if fetching one fails. - Fixed SMTP setup. - Don't let crono overflow the 'log' column on the DB. - Show the actual LDAP error on invalid login. - Fixed the location of crono logs. - Always use relative paths. - Set RUBYLIB when using portusctl. - Don't count hidden teams on the admin panel. - Warn developers on unsupported docker-compose versions. - Directly invalidate LDAP logins without name and password. - Don't show the "I forgot my password" link on LDAP. The following Rubygems bundled within Portus have been updated to fix security issues: - CVE-2016-2098: rubygem-actionpack(bsc#969943). - CVE-2015-7578: rails-html-sanitizer (bsc#963326). - CVE-2015-7579: rails-html-sanitizer (bsc#963327). - CVE-2015-7580: rails-html-sanitizer (bsc#963328). - CVE-2015-7576: rubygem-actionpack, rubygem-activesupport (bsc#963563). - CVE-2015-7577: rubygem-activerecord (bsc#963604). - CVE-2016-0751: rugygem-actionpack (bsc#963627). - CVE-2016-0752: rubygem-actionpack, rubygem-actionview (bsc#963608). - CVE-2016-0753: rubygem-activemodel, rubygem-activesupport, rubygem-activerecord (bsc#963617). - CVE-2015-7581: rubygem-actionpack (bsc#963625). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Containers 12: zypper in -t patch SUSE-SLE-Module-Containers-12-2016-672=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Module for Containers 12 (x86_64): portus-2.0.3-2.4 portus-debuginfo-2.0.3-2.4 portus-debugsource-2.0.3-2.4 References: https://www.suse.com/security/cve/CVE-2015-7576.html https://www.suse.com/security/cve/CVE-2015-7577.html https://www.suse.com/security/cve/CVE-2015-7578.html https://www.suse.com/security/cve/CVE-2015-7579.html https://www.suse.com/security/cve/CVE-2015-7580.html https://www.suse.com/security/cve/CVE-2015-7581.html https://www.suse.com/security/cve/CVE-2016-0751.html https://www.suse.com/security/cve/CVE-2016-0752.html https://www.suse.com/security/cve/CVE-2016-0753.html https://www.suse.com/security/cve/CVE-2016-2098.html https://bugzilla.suse.com/963326 https://bugzilla.suse.com/963327 https://bugzilla.suse.com/963328 https://bugzilla.suse.com/963563 https://bugzilla.suse.com/963604 https://bugzilla.suse.com/963608 https://bugzilla.suse.com/963617 https://bugzilla.suse.com/963625 https://bugzilla.suse.com/963627 https://bugzilla.suse.com/969943 . Criticalpatch for Portus, addressing ten vital vulnerabilities in SUSE, guarantees improved security and reliability.. SUSE Security Update, Portus Security, Linux Container Security. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.