Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

openSUSE: 2023:3144-1 Moderate: Python Tornado Open Redirect Issue

opensuse
Calendar Grey August 2, 2023
Scroller Opensuse
Incremental security enhancement for SUSE Manager Client Utilities, focusing on python-tornado vulnerabilities with remediation guidelines outlined.
This update fixes the following issues: python-tornado:

Description

This update fixes the following issues:

python-tornado:

* Security fixes:

* CVE-2023-28370: Fixed an open redirect issue in the static file handler

(bsc#1211741)

prometheus-blackbox_exporter:

* Use obscpio for go modules service

* Set version number

* Set build date from SOURCE_DATE_EPOCH

* Update to 0.24.0 (bsc#1212279, jsc#PED-4556)

* Requires go1.19

* Avoid empty validation script

* Add rc symlink for backwards compatibility

spacecmd:

* Version 4.3.22-1

* Bypass traditional systems check on older SUMA instances (bsc#1208612)

Patch

## Patch Instructions:

To install this SUSE Moderate update use the SUSE recommended installation

methods like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap Micro 5.3

zypper in -t patch openSUSE-Leap-Micro-5.3-2023-3144=1

* openSUSE Leap Micro 5.4

zypper in -t patch openSUSE-Leap-Micro-5.4-2023-3144=1

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-3144=1

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2023-3144=1

* SUSE Manager Client Tools for SLE 15

zypper in -t patch SUSE-SLE-Manager-Tools-15-2023-3144=1

* SUSE Manager Client Tools for SLE Micro 5

zypper in -t patch SUSE-SLE-Manager-Tools-For-Micro-5-2023-3144=1

* SUSE Linux Enterprise Micro for Rancher 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2023-3144=1

* SUSE Linux Enterprise Micro 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2023-3144=1

* SUSE Linux Enterprise Micro for Rancher 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2023-3144=1

* SUSE Linux Enterprise...

Read the Full Advisory

Package List

* openSUSE Leap Micro 5.3 (aarch64 x86_64)

* python-tornado-debugsource-4.5.3-150000.3.6.1

* python-tornado-debuginfo-4.5.3-150000.3.6.1

* python3-tornado-debuginfo-4.5.3-150000.3.6.1

* python3-tornado-4.5.3-150000.3.6.1

* openSUSE Leap Micro 5.4 (aarch64 s390x x86_64)

* python-tornado-debugsource-4.5.3-150000.3.6.1

* python-tornado-debuginfo-4.5.3-150000.3.6.1

* python3-tornado-debuginfo-4.5.3-150000.3.6.1

* python3-tornado-4.5.3-150000.3.6.1

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)

* python-tornado-debugsource-4.5.3-150000.3.6.1

* python-tornado-debuginfo-4.5.3-150000.3.6.1

* python3-tornado-debuginfo-4.5.3-150000.3.6.1

* python3-tornado-4.5.3-150000.3.6.1

* prometheus-blackbox_exporter-0.24.0-150000.1.20.2

* openSUSE Leap 15.4 (noarch)

* spacecmd-4.3.22-150000.3.101.1

* system-user-prometheus-1.0.0-150000.10.1

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* python-tornado-debugsource-4.5.3-150000.3.6.1

* python-tornado-debuginfo-4.5.3-150000.3.6.1

*...

Read the Full Advisory

References

* #1208612

* #1211741

* #1212279

## References:

* https://www.suse.com/security/cve/CVE-2023-28370.html

* https://bugzilla.suse.com/show_bug.cgi?id=1208612

* https://bugzilla.suse.com/show_bug.cgi?id=1211741

* https://bugzilla.suse.com/show_bug.cgi?id=1212279

*

*

*

Announcement ID: SUSE-SU-2023:3144-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.