Bugzilla – Bug 1216571
VUL-1: HAWK: Improve CSRF protection
Last modified: 2024-01-31 12:30:29 UTC
In app/controllers/errors_controller.rb ,line 5, the CSRF protection is configured as is: protect_from_forgery(:with => :null_session). Instead, it CSRF protection should be configured with `with: :exception`
SUSE-SU-2024:0076-1: An update that has eight security fixes can now be installed. Category: security (moderate) Bug References: 1206217, 1207930, 1208533, 1213454, 1215438, 1215976, 1216508, 1216571 Sources used: openSUSE Leap 15.4 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 openSUSE Leap 15.5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 SUSE Linux Enterprise High Availability Extension 15 SP1 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 SUSE Linux Enterprise High Availability Extension 15 SP2 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 SUSE Linux Enterprise High Availability Extension 15 SP3 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 SUSE Linux Enterprise High Availability Extension 15 SP4 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 SUSE Linux Enterprise High Availability Extension 15 SP5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.39.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-RU-2024:0282-1: An update that has eight fixes can now be installed. Category: recommended (moderate) Bug References: 1206217, 1207930, 1208533, 1213454, 1215438, 1215976, 1216508, 1216571 Sources used: openSUSE Leap 15.5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 SUSE Linux Enterprise High Availability Extension 15 SP1 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 SUSE Linux Enterprise High Availability Extension 15 SP2 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 SUSE Linux Enterprise High Availability Extension 15 SP3 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 SUSE Linux Enterprise High Availability Extension 15 SP4 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 SUSE Linux Enterprise High Availability Extension 15 SP5 (src): hawk2-2.6.4+git.1702030539.5fb7d91b-150000.3.42.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.