Description of the patch:
This update for rmt-server fixes the following issues:
Update to version 2.27.
Security issues fixed:
header_rules bypass (bsc#1261426).Range headers can lead to
excessive resource consumption and a denial of service (bsc#1261436).Content-Length header can lead to unbounded chunked file uploads
and a denial of service (bsc#1261447).Accept-Encoding headers can lead to a denial
of service (bsc#1261388).X-Accel-Mapping request header can lead to the exposure of
unintended files via X-Accel-Redirect (bsc#1261458).Content-Length header and body byte size mismatch when creating error responses can lead to
incorrect HTTP response framing (bsc#1261466).Other updates and bugfixes:
Addressable.rdiscount.2.27-150700.3.20.12.27-150700.3.20.12.27-150700.3.20.1Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:NI:NA:H7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H