SUSE-SU-2023:0812-1
Vulnerability Summary
Timeline
Description
Security update for SUSE Manager Client Tools This update fixes the following issues: dracut-saltboot: - Update to verion 0.1.1674034019.a93ff61 * Install copied wicked config as client.xml (bsc#1205599) - Update to version 0.1.1673279145.e7616bd grafana: - CVE-2022-46146: Fix basic authentication bypass by updating the exporter toolkit to version 0.7.3 (bsc#1208065,) - CVE-2022-41723: Require Go 1.19 or newer (bsc#1208293) - Update to version 8.5.20: * CVE-2022-23552: Security: SVG: Add dompurify preprocessor step (bsc#1207749) * CVE-2022-39324: Security: Snapshots: Fix originalUrl spoof security issue (bsc#1207750) * Security: Omit error from http response * Bug fix: Email and username trimming and invitation validation spacecmd: - Version 4.3.19-1 * Fix spacecmd not showing any output for softwarechannel_diff and softwarechannel_errata_diff (bsc#1207352) * Prevent string api parameters to be parsed as dates if not in ISO-8601 format (bsc#1205759) spacewalk-client-tools: - Version 4.3.15-1 * Update translation strings supportutils-plugin-salt: - Update to version 1.2.2 * Remove possible passwords from Salt configuration files (bsc#1201059) uyuni-proxy-systemd-services: - Version 4.3.8-1 * Allow using container images from different registry paths
Affected Systems
- opensuse•dracut-saltboot&distro=openSUSE Leap 15.4
< 0.1.1674034019.a93ff61-150000.1.47.1
- opensuse•spacecmd&distro=openSUSE Leap 15.4
< 4.3.19-150000.3.95.1
- opensuse•supportutils-plugin-salt&distro=openSUSE Leap 15.4
< 1.2.2-150000.3.13.1
- suse•dracut-saltboot&distro=SUSE Manager Client Tools 15
< 0.1.1674034019.a93ff61-150000.1.47.1
- suse•dracut-saltboot&distro=SUSE Manager Client Tools for SLE Micro 5
< 0.1.1674034019.a93ff61-150000.1.47.1
- suse•grafana&distro=SUSE Manager Client Tools 15
< 8.5.20-150000.1.42.1
- suse•spacecmd&distro=SUSE Manager Client Tools 15
< 4.3.19-150000.3.95.1
- suse•spacewalk-client-tools&distro=SUSE Manager Client Tools 15
< 4.3.15-150000.3.77.1
- suse•supportutils-plugin-salt&distro=SUSE Enterprise Storage 7
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Enterprise Storage 7.1
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise Module for Basesystem 15 SP4
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise Real Time 15 SP3
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise Server 15 SP1-LTSS
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise Server 15 SP2-LTSS
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise Server 15 SP3-LTSS
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP1
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP3
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Manager Client Tools 15
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Manager Proxy 4.2
< 1.2.2-150000.3.13.1
- suse•supportutils-plugin-salt&distro=SUSE Manager Server 4.2
< 1.2.2-150000.3.13.1
- suse•uyuni-proxy-systemd-services&distro=SUSE Manager Client Tools 15
< 4.3.8-150000.1.12.1
- suse•uyuni-proxy-systemd-services&distro=SUSE Manager Client Tools for SLE Micro 5
< 4.3.8-150000.1.12.1
References (13)
- https://www.suse.com/support/update/announcement/2023/suse-su-20230812-1/
- https://bugzilla.suse.com/1201059
- https://bugzilla.suse.com/1205599
- https://bugzilla.suse.com/1205759
- https://bugzilla.suse.com/1207352
- https://bugzilla.suse.com/1207749
- https://bugzilla.suse.com/1207750
- https://bugzilla.suse.com/1208065
- https://bugzilla.suse.com/1208293
- https://www.suse.com/security/cve/CVE-2022-23552
- https://www.suse.com/security/cve/CVE-2022-39324
- https://www.suse.com/security/cve/CVE-2022-41723
- https://www.suse.com/security/cve/CVE-2022-46146