SUSE-FU-2024:2078-1

Advisory lineage Upstream: 5 Downstream: 0
Published: 19 Jun 2024, 03:36
Last modified:04 Feb 2026, 04:37

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Jun 2024, 03:36
Published
Vulnerability first disclosed
04 Feb 2026, 04:37
Last Modified
Vulnerability information updated

Description

Feature update for rabbitmq-server313, erlang26, elixir115 This update for rabbitmq-server313, erlang26, elixir115 fixes the following issues: rabbitmq-server was implemented with a parallel versioned RPM package at version 3.13.1 (jsc#PED-8414): - Security issues fixed: * CVE-2021-22116: Fixed improper input validation that may lead to Denial of Sercice (DoS) attacks (bsc#1186203) * CVE-2021-32718, CVE-2021-32719: Fixed potential for JavaScript code execution in the management UI (bsc#1187818, bsc#1187819) * CVE-2022-31008: Fixed encryption key used to encrypt the URI was seeded with a predictable secret (bsc#1205267) * CVE-2023-46118: Fixed HTTP API vulnerability for denial of service (DoS) attacks with very large messages (bsc#1216582) - Other bugs fixed: * Fixed RabbitMQ maintenance status issue (bsc#1199431) * Provide user/group for RPM 4.19 (bsc#1219532) * Fixed `rabbitmqctl` command for `add_user` (bsc#1222591) * Added hardening to systemd service(s) (bsc#1181400) * Use /run instead of deprecated /var/run in tmpfiles.conf (bsc#1185075) - For the full list of upstream changes of this update between version 3.8.11 and 3.13.1 please consult: * https://www.rabbitmq.com/release-information erlang26: - Provide RPM package as it's a dependency of rabbitmq-server313 (jsc#PED-8414) elixir115: - Provide RPM package as needed in some cases by rabbitmq-server313 (jsc#PED-8414)

Affected Systems

  • opensuseelixir115&distro=openSUSE Leap 15.6

    < 1.15.7-150300.7.5.1

  • opensuseerlang26&distro=openSUSE Leap 15.6

    < 26.2.1-150300.7.5.1

  • opensuserabbitmq-server313&distro=openSUSE Leap 15.6

    < 3.13.1-150600.13.5.3

  • suseelixir115&distro=SUSE Linux Enterprise Module for Server Applications 15 SP6

    < 1.15.7-150300.7.5.1

  • suseerlang26&distro=SUSE Linux Enterprise Module for Server Applications 15 SP6

    < 26.2.1-150300.7.5.1

  • suserabbitmq-server313&distro=SUSE Linux Enterprise Module for Server Applications 15 SP6

    < 3.13.1-150600.13.5.3

References (16)