SUSE-SU-2023:0352-1

Published: 10 Feb 2023, 14:12
Last modified:04 Feb 2026, 03:31

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Feb 2023, 14:12
Published
Vulnerability first disclosed
04 Feb 2026, 03:31
Last Modified
Vulnerability information updated

Description

Security update for SUSE Manager Client Tools This update fixes the following issues: grafana: - Update to version 8.5.15 (jsc#PED-2617): * CVE-2022-39306: Fix for privilege escalation (bsc#1205225) * CVE-2022-39307: Omit error from http response when user does not exists (bsc#1205227) - Update to version 8.5.14: * CVE-2022-39201: Fix do not forward login cookie in outgoing requests (bsc#1204303) * CVE-2022-31130: Make proxy endpoints not leak sensitive HTTP headers (bsc#1204305) * CVE-2022-31123: Fix plugin signature bypass (bsc#1204302) * CVE-2022-39229: Fix blocknig other users from signing in (bsc#1204304) kiwi-desc-saltboot: - Update to version 0.1.1673279145.e7616bd * Add failsafe stop file when salt-minion does not stop (bsc#1172110) mgr-osad: - Version 4.3.7-1 * Updated logrotate configuration (bsc#1206470) mgr-push: - Version 4.3.5-1 * Update translation strings rhnlib: - Version 4.3.5-1 * Don't get stuck at the end of SSL transfers (bsc#1204032) spacecmd: - Version 4.3.18-1 * Add python-dateutil dependency, required to process date values in spacecmd api calls - Version 4.3.17-1 * Remove python3-simplejson dependency * Correctly understand 'ssm' keyword on scap scheduling * Add vendor_advisory information to errata_details call (bsc#1205207) * Added two missing options to schedule product migration: allow-vendor-change and remove-products-without-successor (bsc#1204126) * Changed schedule product migration to use the correct API method * Change default port of 'Containerized Proxy configuration' 8022 spacewalk-client-tools: - Version 4.3.14-1 * Update translation strings uyuni-common-libs: - Version 4.3.7-1 * unify user notification code on java side

Affected Systems

  • susegrafana&distro=SUSE Manager Client Tools 12

    < 8.5.15-1.39.1

  • susekiwi-desc-saltboot&distro=SUSE Manager Client Tools 12

    < 0.1.1673279145.e7616bd-1.32.1

  • susemgr-osad&distro=SUSE Manager Client Tools 12

    < 4.3.7-1.42.1

  • susemgr-push&distro=SUSE Manager Client Tools 12

    < 4.3.5-1.24.1

  • suserhnlib&distro=SUSE Manager Client Tools 12

    < 4.3.5-21.46.1

  • susespacecmd&distro=SUSE Manager Client Tools 12

    < 4.3.18-38.115.1

  • susespacewalk-client-tools&distro=SUSE Manager Client Tools 12

    < 4.3.14-52.83.1

  • suseuyuni-common-libs&distro=SUSE Manager Client Tools 12

    < 4.3.7-1.30.1

References (18)