Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update fixes the following issues:
dracut-saltboot:
- Update to version 0.1.1673279145.e7616bd
* Add failsafe stop file when salt-minion does not stop (bsc#1172110)
* Copy existing wicked config instead of generating new (bsc#1205599)
grafana:
- Update to version 8.5.15 (jsc#PED-2617):
* CVE-2022-39306: Fix for privilege escalation (bsc#1205225)
* CVE-2022-39307: Omit error from http response when user does not
exists (bsc#1205227)
- Update to version 8.5.14:
* CVE-2022-39201: Fix do not forward login cookie in outgoing requests
(bsc#1204303)
* CVE-2022-31130: Make proxy endpoints not leak sensitive HTTP headers
(bsc#1204305)
* CVE-2022-31123: Fix plugin signature bypass (bsc#1204302)
* CVE-2022-39229: Fix blocknig other users from signing in (bsc#1204304)
mgr-osad:
- Version 4.3.7-1
* Updated logrotate configuration (bsc#1206470)
mgr-push:
- Version 4.3.5-1
* Update...
Read the Full AdvisoryPatch Instructions:
To install this SUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.4:
zypper in -t patch openSUSE-SLE-15.4-2023-353=1
- SUSE Manager Tools for SLE Micro 5:
zypper in -t patch SUSE-SLE-Manager-Tools-For-Micro-5-2023-353=1
- SUSE Manager Tools 15:
zypper in -t patch SUSE-SLE-Manager-Tools-15-2023-353=1
- openSUSE Leap 15.4 (noarch):
dracut-saltboot-0.1.1673279145.e7616bd-150000.1.44.1
spacecmd-4.3.18-150000.3.92.1
- SUSE Manager Tools for SLE Micro 5 (noarch):
dracut-saltboot-0.1.1673279145.e7616bd-150000.1.44.1
- SUSE Manager Tools 15 (aarch64 ppc64le s390x x86_64):
grafana-8.5.15-150000.1.39.1
grafana-debuginfo-8.5.15-150000.1.39.1
python3-uyuni-common-libs-4.3.7-150000.1.30.1
- SUSE Manager Tools 15 (noarch):
dracut-saltboot-0.1.1673279145.e7616bd-150000.1.44.1
mgr-osad-4.3.7-150000.1.42.1
mgr-push-4.3.5-150000.1.24.2
python3-mgr-osa-common-4.3.7-150000.1.42.1
python3-mgr-osad-4.3.7-150000.1.42.1
python3-mgr-push-4.3.5-150000.1.24.2
python3-rhnlib-4.3.5-150000.3.40.1
python3-spacewalk-check-4.3.14-150000.3.74.1
python3-spacewalk-client-setup-4.3.14-150000.3.74.1
python3-spacewalk-client-tools-4.3.14-150000.3.74.1
spacecmd-4.3.18-150000.3.92.1
spacewalk-check-4.3.14-150000.3.74.1
spacewalk-client-setup-4.3.14-150000.3.74.1
spacewalk-client-tools-4.3.14-150000.3.74.1
https://www.suse.com/security/cve/CVE-2022-31123.html
https://www.suse.com/security/cve/CVE-2022-31130.html
https://www.suse.com/security/cve/CVE-2022-39201.html
https://www.suse.com/security/cve/CVE-2022-39229.html
https://www.suse.com/security/cve/CVE-2022-39306.html
https://www.suse.com/security/cve/CVE-2022-39307.html
https://bugzilla.suse.com/1172110
https://bugzilla.suse.com/1204032
https://bugzilla.suse.com/1204126
https://bugzilla.suse.com/1204302
https://bugzilla.suse.com/1204303
https://bugzilla.suse.com/1204304
https://bugzilla.suse.com/1204305
https://bugzilla.suse.com/1205207
https://bugzilla.suse.com/1205225
https://bugzilla.suse.com/1205227
https://bugzilla.suse.com/1205599
https://bugzilla.suse.com/1206470
Get the latest Linux and open source security news straight to your inbox.