openSUSE Recommended Update: Recommended update for cacti, cacti-spine ______________________________________________________________________________ Announcement ID: openSUSE-RU-2020:1167-1 Rating: moderate References: #1174850 Affected Products: openSUSE Leap 15.2 openSUSE Leap 15.1 SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that has one recommended fix can now be installed. Description: This update for cacti, cacti-spine fixes the following issues: Updated to version 1.2.14 - Fixed an XSS vulnerability due to improper escaping of error message during template import preview (boo#1174850). Patch Instructions: To install this openSUSE Recommended Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1167=1 - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-1167=1 - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2020-1167=1 Package List: - openSUSE Leap 15.2 (x86_64): cacti-spine-1.2.14-lp152.2.6.1 cacti-spine-debuginfo-1.2.14-lp152.2.6.1 cacti-spine-debugsource-1.2.14-lp152.2.6.1 - openSUSE Leap 15.2 (noarch): cacti-1.2.14-lp152.2.6.1 - openSUSE Leap 15.1 (noarch): cacti-1.2.14-lp151.3.15.1 - openSUSE Leap 15.1 (x86_64): cacti-spine-1.2.14-lp151.3.15.1 cacti-spine-debuginfo-1.2.14-lp151.3.15.1 cacti-spine-debugsource-1.2.14-lp151.3.15.1 - SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64): cacti-spine-1.2.14-11.1 - SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 s390x x86_64): cacti-spine-debuginfo-1.2.14-11.1 cacti-spine-debugsource-1.2.14-11.1 - SUSE Package Hub for SUSE Linux Enterprise 12 (noarch): cacti-1.2.14-14.1 References: https://bugzilla.suse.com/1174850