Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

openSUSE 15.1: Security Advisory for Icingaweb2 Update: Moderate Issues

opensuse
Calendar Grey January 16, 2020
Scroller Opensuse
A recent update addresses various bugs and security vulnerabilities affecting icingaweb2 on openSUSE. Discover the solutions implemented and the procedures for updating your installation.
An update that solves 5 vulnerabilities and has one errata is now available.

Description

This update for icingaweb2 to version 2.7.3 fixes the following issues:

icingaweb2 update to 2.7.3:

* Fixed an issue where servicegroups for roles with filtered objects were

not available

icingaweb2 update to 2.7.2:

* Performance imrovements and bug fixes

icingaweb2 update to 2.7.1:

* Highlight links in the notes of an object

* Fixed an issue where sort rules were no longer working

* Fixed an issue where statistics were shown with an anarchist way

* Fixed an issue where wildcards could no show results

icingaweb2 update to 2.7.0:

* New languages support

* Now module developers got additional ways to customize Icinga Web 2

* UI enhancements

icingaweb2 update to 2.6.3:

* Fixed various issues with LDAP

* Fixed issues with timezone

* UI enhancements

* Stability fixes

icingaweb2 update to 2.6.2:

You can find issues and features related to this release on our Roadmap.

This bugfix release addresses the...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-67=1

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2020-67=1

- openSUSE Backports SLE-15-SP1:

zypper in -t patch openSUSE-2020-67=1

- openSUSE Backports SLE-15:

zypper in -t patch openSUSE-2020-67=1

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2020-67=1

Package List

- openSUSE Leap 15.1 (noarch):

icingacli-2.7.3-lp151.6.5.1

icingaweb2-2.7.3-lp151.6.5.1

icingaweb2-common-2.7.3-lp151.6.5.1

icingaweb2-vendor-HTMLPurifier-2.7.3-lp151.6.5.1

icingaweb2-vendor-JShrink-2.7.3-lp151.6.5.1

icingaweb2-vendor-Parsedown-2.7.3-lp151.6.5.1

icingaweb2-vendor-dompdf-2.7.3-lp151.6.5.1

icingaweb2-vendor-lessphp-2.7.3-lp151.6.5.1

icingaweb2-vendor-zf1-2.7.3-lp151.6.5.1

php-Icinga-2.7.3-lp151.6.5.1

- openSUSE Leap 15.0 (noarch):

icingacli-2.7.3-lp150.4.7.1

icingaweb2-2.7.3-lp150.4.7.1

icingaweb2-common-2.7.3-lp150.4.7.1

icingaweb2-vendor-HTMLPurifier-2.7.3-lp150.4.7.1

icingaweb2-vendor-JShrink-2.7.3-lp150.4.7.1

icingaweb2-vendor-Parsedown-2.7.3-lp150.4.7.1

icingaweb2-vendor-dompdf-2.7.3-lp150.4.7.1

icingaweb2-vendor-lessphp-2.7.3-lp150.4.7.1

icingaweb2-vendor-zf1-2.7.3-lp150.4.7.1

php-Icinga-2.7.3-lp150.4.7.1

- openSUSE Backports SLE-15-SP1 (noarch):

icingacli-2.7.3-bp151.5.3.1

icingaweb2-2.7.3-bp151.5.3.1

icingaweb2-common-2.7.3-bp151.5.3.1

icingaweb2-vendor-HTMLPurifier-2.7.3-bp151.5.3.1

icing...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-18246.html

https://www.suse.com/security/cve/CVE-2018-18247.html

https://www.suse.com/security/cve/CVE-2018-18248.html

https://www.suse.com/security/cve/CVE-2018-18249.html

https://www.suse.com/security/cve/CVE-2018-18250.html

https://bugzilla.suse.com/1101357

https://bugzilla.suse.com/1119784

https://bugzilla.suse.com/1119785

https://bugzilla.suse.com/1119799

https://bugzilla.suse.com/1119800

https://bugzilla.suse.com/1119801

--

Announcement ID: openSUSE-SU-2020:0067-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 openSUSE Leap 15.0 openSUSE Backports SLE-15-SP1 openSUSE Backports SLE-15 SUSE Package Hub for SUSE Linux Enterprise 12 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.