SUSE-SU-2024:1507-1

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 06 May 2024, 09:46
Last modified:04 Feb 2026, 03:52

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 May 2024, 09:46
Published
Vulnerability first disclosed
04 Feb 2026, 03:52
Last Modified
Vulnerability information updated

Description

Security update for SUSE Manager Server 4.3 This update fixes the following issues: cobbler: - Provide option to use pre-built GRUB bootloader - Prevent parallel executions of cobbler sync actions (bsc#1218764) image-sync-formula: - Update to version 0.1.1711646883.4a44375 * Add missing URL tag * Update license to SPDX syntax inter-server-sync: - Version 0.3.3-1 * Correct primary key export for table suseproductsccrepository (bsc#1220169) jose4j: - CVE-2023-51775: Fix denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value (bsc#1220726) smdba: - Version 1.7.13 * postmaster no longer exists from >=16 and it's an alias for postgresql, using postgresql command spacecmd: - Version 4.3.27-0 * Update translation strings spacewalk-backend: - Version 4.3.28-0 * Strip whitespace from .deb package metadata (bsc#1214387) * Fix inserting NULL into some columns during ISSv1 sync (bsc#1220980) * Add support for package signature type V4 RSA/SHA512 (bsc#1221465) * Unquote HTML-encoded credentials before synchronizing repositories (bsc#1217204) spacewalk-certs-tools: - Version 4.3.23-0 * Fix liberty bootstrapping when zypper is installed (bsc#1222347) * Apply reboot method changes for transactional systems in the bootstrap script spacewalk-client-tools: - Version 4.3.19-0 * Update translation strings spacewalk-config: - Version 4.3.13-0 * Be explicit about default Apache configs being overwritten on updates and point to making custom configs. (bsc#1219061) spacewalk-java: - Version 4.3.73-0 * New API endpoint for getRelevantErrata. It takes multiple servers as argument and it returns an array of maps representing the errata that can be applied to each system - Version 4.3.72-0 * Use execution module call to detect client instance flavor (PAYG/BYOS) in public cloud (bsc#1218805) * Update help text for the custom repo filter field (bsc#1217874) * Fix issue where Salt cannot access autoinstallation files (bsc#1220221) * Fix issue when checking for credential duplication (bsc#1218957) * Fix matching epoch while creating Ubuntu erratas * When an action that belongs to an action chain is unscheduled, unschedule the action chain as well (bsc#1221784) * Reschedule failed SSH actions caused by a connection error due to a scheduled reboot * Fix removal of old IPv6 addresses (bsc#1214340) * Do not automatically add child channels outside of selected base channel (bsc#1220101) * Fix listProxies API call (bsc#1219233) * Fix system.provisionSystem when called via HTTP API (bsc#1219875) * Remove package sync not available message in Software > Packages > Profile since it is no longer available for supported clients (bsc#1221279) * Fix login for read-only users when using HTTP API (bsc#1221111) * Add one-shot action execution to recurring custom state create/edit * Fix a typo in 'Deploy Files' page * Drop system password as identifier on SCC system registration (bsc#1219634, bsc#1221182) * Fix memory size extraction in virtual instances (bsc#1219634) * Fix virtual systems filters (bsc#1208572) * Update license to include the year 2024 * Add timeout for SMTP server connection (bsc#1218931) * Commit Salt event removal in case of process failure (bsc#1218931) * Users with API read only are only allowed to make GET requests * Ignore retry suffix when getting recurring action id from schedule name * Sort CLM project filters by filter name spacewalk-web: - Version 4.3.38-0 * Upgrade json5 to 2.2.3 * Upgrade semver to 7.6.0 * Add one-shot action execution to recurring custom state create/edit * Fix virtual systems filters (bsc#1208572) * Improve CLM Create New Filter button * Bump the WebUI version to 4.3.12 subscription-matcher: - Version 0.37 * add missing part number (bsc#1221922) * Fix penalties logging by initializing the score director consistently - Removed wrong apache-commons-lang dependency - Version 0.36 * Fixed Log4j 2 initialization supportutils-plugin-susemanager: - Version 4.3.11-0 * Add Salt and Reposync connections to minimum required DB connections calculation susemanager: - Version 4.3.35-0 * Add bootstrap repository definition for openSUSE Leap 15.6 * Add bootstrap repository definition for SUSE Linux Enterprise 15 SP6 susemanager-docs_en: - Removed Debian 10 from the list of supported clients - Added new workflow describing updating of clients using recurring actions to Commown Workflows - Added documentation on adding a storage device for VMWare - Documented registercloudguest tools for registering public cloud installation (BYOS) by adding a reference to the Public Cloud Guide - Added information about requirements for the PostgreSQL database to the Installation and Upgrade Guide (bsc#1220376) - Fixed the instructions for SSL Certificates (bsc#1219061) - Remove package sync paragraph in package-management doc since it is not available for Salt clients and traditional clients are no longer supported (bsc#1221279) - Fixed incorrect reference to SUSE Linux Enterprise Server 15 SP5 as base product for SUSE Manager 4.3, even in public cloud - Updated VM based installation for 4.3 VM image with ignition or cloudinit in Installation and Upgrade Guide - Added reference from Hub documentation to Inter-Server Synchronization in Large Deployment Guide - Documented Virtualization Guest and Virtualization Host Formula - Reformatted Supported Clients tables in Client Configuration Guide and Installation and Upgrade Guide - Add documentation about SMTP timeout configuration - Documented SSH key rotation in Salt Guide (bsc#1170848) - Documented liberate formula in Salt Guide - Fixed Prepare on-demand images section in Client Configuration - Fixed a changed configuration parameter for salt-ssh - Added Pay-as-you-go on the Cloud: FAQ document - Updated max-connections tuning recommendation in Large Deployment - Added troubleshooting instructions for setting up in public cloud (BYOS) to Administration Guide - Added section about migrating Enterprise Linux (EL) clients to SUSE Liberty Linux to Client Configuration Guide - Added detailed information about the messages produced by subscription matcher - Added Pay-as-you-go as supported service on Azure to the Public Cloud Guide - Added and fixed configuration details in Troubleshooting Renaming Server in Administration Guide susemanager-schema: - Version 4.3.25-0 * Add update-salt to internal state table susemanager-sls: - Version 4.3.41-0 * Use execution module call to detect client instance flavor (PAYG/BYOS) in public cloud (bsc#1218805) * Do not log dnf needs-restarting output in Salt's log (bsc#1220194) * Dynamically load an SELinux policy for 'Push via SSH tunnel' for SELinux enabled clients. This policy allows communication over a custom SSH port * Fix reboot needed detection for SUSE systems * Fix SUSE Liberty Linux bootstrapping when Zypper is installed (bsc#1222347) * Distinguish between different SUSE versions when detecting if a reboot is needed (bsc#1220903, bsc#1221571) * Improve updatestack update in uptodate state * Add a standalone update-salt state * Add pillar check to skip reboot_if_needed state * Recognize .tar.xz and .ext4 image files (bsc#1216085) * Avoid issues on reactivating traditional clients as Salt managed * Fix the case of missing requisites on bootstrap (bsc#1220705) susemanager-sync-data: - Version 4.3.17-0 * AlmaLinux 9 PowerTools was renamed into CRB (bsc#1222110) uyuni-common-libs: - Version 4.3.10-0 * Add support for package signature type V4 RSA/SHA384 * Add support for package signature type V4 RSA/SHA512 (bsc#1221465) uyuni-reportdb-schema: - Version 4.3.10-0 * Provide reportdb upgrade schema path structure How to apply this update: 1. Log in as root user to the SUSE Manager Server. 2. Stop the Spacewalk service: `spacewalk-service stop` 3. Apply the patch using either zypper patch or YaST Online Update. 4. Start the Spacewalk service: `spacewalk-service start`

Affected Systems

  • susecobbler&distro=SUSE Manager Server Module 4.3

    < 3.3.3-150400.5.42.5

  • suseimage-sync-formula&distro=SUSE Manager Server Module 4.3

    < 0.1.1711646883.4a44375-150400.3.18.4

  • suseinter-server-sync&distro=SUSE Manager Server Module 4.3

    < 0.3.3-150400.3.30.4

  • susejose4j&distro=SUSE Manager Server Module 4.3

    < 0.5.1-150400.3.9.4

  • susemgr-daemon&distro=SUSE Manager Proxy Module 4.3

    < 4.3.9-150400.3.15.5

  • susesmdba&distro=SUSE Manager Server Module 4.3

    < 1.7.13-0.150400.4.12.4

  • susespacecmd&distro=SUSE Manager Proxy Module 4.3

    < 4.3.27-150400.3.36.5

  • susespacecmd&distro=SUSE Manager Server Module 4.3

    < 4.3.27-150400.3.36.5

  • susespacewalk-backend&distro=SUSE Manager Proxy Module 4.3

    < 4.3.28-150400.3.41.7

  • susespacewalk-backend&distro=SUSE Manager Server Module 4.3

    < 4.3.28-150400.3.41.7

  • susespacewalk-certs-tools&distro=SUSE Manager Proxy Module 4.3

    < 4.3.23-150400.3.28.5

  • susespacewalk-certs-tools&distro=SUSE Manager Server Module 4.3

    < 4.3.23-150400.3.28.5

  • susespacewalk-client-tools&distro=SUSE Manager Proxy Module 4.3

    < 4.3.19-150400.3.27.5

  • susespacewalk-client-tools&distro=SUSE Manager Server Module 4.3

    < 4.3.19-150400.3.27.5

  • susespacewalk-config&distro=SUSE Manager Server Module 4.3

    < 4.3.13-150400.3.15.5

  • susespacewalk-java&distro=SUSE Manager Server Module 4.3

    < 4.3.73-150400.3.79.1

  • susespacewalk-web&distro=SUSE Manager Proxy Module 4.3

    < 4.3.38-150400.3.42.6

  • susespacewalk-web&distro=SUSE Manager Server Module 4.3

    < 4.3.38-150400.3.42.6

  • susesubscription-matcher&distro=SUSE Manager Server Module 4.3

    < 0.37-150400.3.22.4

  • susesupportutils-plugin-susemanager&distro=SUSE Manager Server Module 4.3

    < 4.3.11-150400.3.21.4

  • susesusemanager-docs_en&distro=SUSE Manager Server Module 4.3

    < 4.3-150400.9.56.4

  • susesusemanager-schema&distro=SUSE Manager Server Module 4.3

    < 4.3.25-150400.3.39.5

  • susesusemanager-sls&distro=SUSE Manager Server Module 4.3

    < 4.3.41-150400.3.47.6

  • susesusemanager-sync-data&distro=SUSE Manager Server Module 4.3

    < 4.3.17-150400.3.25.4

  • susesusemanager&distro=SUSE Manager Server Module 4.3

    < 4.3.35-150400.3.48.6

  • suseuyuni-common-libs&distro=SUSE Manager Proxy Module 4.3

    < 4.3.10-150400.3.18.4

  • suseuyuni-common-libs&distro=SUSE Manager Server Module 4.3

    < 4.3.10-150400.3.18.4

  • suseuyuni-reportdb-schema&distro=SUSE Manager Server Module 4.3

    < 4.3.10-150400.3.15.6

References (35)