[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-EL-9-CLIENT-TOOLS-2025-4474":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T17:35:29.592Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":18,"duplicates":19,"related":20,"reserved_at":9,"published_at":23,"modified_at":24,"state":9,"summary":25,"references_raw":27,"kevs":76,"epss":9,"epss_history":77,"metrics":78,"affected":79},"SUSE-EL-9-CLIENT-TOOLS-2025-4474","Security update 5.0.6 for Multi-Linux Manager Salt Bundle\n\nThis update fixes the following issues:\n\nvenv-salt-minion:\n\n- Security issues fixed:\n\n  - CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257)\n  - CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256)\n  - Backport security fixes for vendored tornado\n    * BDSA-2024-3438\n    * BDSA-2024-3439\n    * BDSA-2024-9026\n\n- Other changes and bugs fixed:\n\n  - Fixed TLS and x509 modules for OSes with older cryptography module\n  - Fixed Salt for Python > 3.11 (bsc#1252285, bsc#1252244)\n    * Use external tornado on Python > 3.11\n    * Make tls and x509 to use python-cryptography\n    * Remove usage of spwd\n  - Fixed payload signature verification on Tumbleweed (bsc#1251776)\n  - Fixed broken symlink on migration to Leap 16.0 (bsc#1250755)\n  - Fixed known_hosts error on gitfs (bsc#1250520, bsc#1227207)\n\n",null,[],[],[],[14,16],{"_key":15},"CVE-2025-62348",{"_key":17},"CVE-2025-62349",[],[],[21,22],{"_key":15},{"_key":17},"2025-12-18T12:07:57Z","2026-07-24T18:24:19.736913716Z",{"cisa_kev":26,"cisa_ransomware":26,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[28,34,39,43,47,51,55,59,63,67,72],{"url":29,"sources":30,"tags":32},"https://www.suse.com/support/update/announcement//suse-el-9-client-tools-2025-4474/",[31],"osv_suse",[33],"Advisory",{"url":35,"sources":36,"tags":37},"https://bugzilla.suse.com/1227207",[31],[38],"REPORT",{"url":40,"sources":41,"tags":42},"https://bugzilla.suse.com/1245740",[31],[38],{"url":44,"sources":45,"tags":46},"https://bugzilla.suse.com/1250520",[31],[38],{"url":48,"sources":49,"tags":50},"https://bugzilla.suse.com/1251776",[31],[38],{"url":52,"sources":53,"tags":54},"https://bugzilla.suse.com/1252244",[31],[38],{"url":56,"sources":57,"tags":58},"https://bugzilla.suse.com/1252285",[31],[38],{"url":60,"sources":61,"tags":62},"https://bugzilla.suse.com/1254256",[31],[38],{"url":64,"sources":65,"tags":66},"https://bugzilla.suse.com/1254257",[31],[38],{"url":68,"sources":69,"tags":70},"https://www.suse.com/security/cve/CVE-2025-62348",[31],[71],"WEB",{"url":73,"sources":74,"tags":75},"https://www.suse.com/security/cve/CVE-2025-62349",[31],[71],[],[],[],[80],{"ecosystem":81,"name":82,"vendor":83,"product":84,"cpe_part":9,"purl_type":85,"purl_namespace":83,"purl_name":84,"source":9,"versions":86},"SUSE Linux Enterprise","venv-salt-minion","suse","venv-salt-minion&distro=SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS","rpm",[87],{"version":88,"is_range":89,"range_type":90,"version_start":9,"version_start_type":9,"version_end":91,"version_end_type":92,"fixed_in":9},"lt3006_0_1_64_1",true,"ecosystem","3006.0-1.64.1","excluding"]