Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update fixes the following issues:
golang-github-lusitaniae-apache_exporter:
* Security issues fixed:
* CVE-2022-32149: Fix denial of service vulnerability (bsc#1204501)
* CVE-2022-41723: Fix uncontrolled resource consumption (bsc#1208270)
* CVE-2022-46146: Fix authentication bypass vulnarability (bsc#1208046)
* Changes and bugs fixed:
* Updated to 1.0.0 (jsc#PED-5405)
* Improved flag parsing
* Added support for custom headers
* Changes from 0.13.1
* Fix panic caused by missing flagConfig options
* Added AppArmor profile
* Added sandboxing options to systemd service unit
* Build using promu
* Build with Go 1.19
* Exclude s390 architecture
golang-github-prometheus-prometheus:
* This update introduces breaking changes. Please, read carefully the provided
informations.
* Security issues fixed:
* CVE-2022-41723: Fix uncontrolled resource consumption by updating Go to
version 1.20.1 (bsc#1208298)
* Updated to 2.45.0 (jsc#PED-5406):
* [FEATURE] API: New limit...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch openSUSE-SLE-15.4-2023-3868=1
* openSUSE Leap 15.5
zypper in -t patch openSUSE-SLE-15.5-2023-3868=1
* SUSE Manager Client Tools for SLE 15
zypper in -t patch SUSE-SLE-Manager-Tools-15-2023-3868=1
* SUSE Manager Client Tools for SLE Micro 5
zypper in -t patch SUSE-SLE-Manager-Tools-For-Micro-5-2023-3868=1
* SUSE Manager Proxy 4.2 Module 4.2
zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.2-2023-3868=1
* SUSE Manager Proxy 4.3 Module 4.3
zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.3-2023-3868=1
* SUSE Manager Server 4.2 Module 4.2
zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Server-4.2-2023-3868=1
* SUSE Manager Server 4.3 Module 4.3
zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Server-4.3-2023-3868=1
* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)
* golang-github-QubitProducts-exporter_exporter-0.4.0-150000.1.18.3
* golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.17.2
* prometheus-postgres_exporter-0.10.1-150000.1.14.3
* golang-github-lusitaniae-apache_exporter-debuginfo-1.0.0-150000.1.17.2
* prometheus-blackbox_exporter-0.24.0-150000.1.23.3
* openSUSE Leap 15.4 (noarch)
* supportutils-plugin-susemanager-client-4.3.3-150000.3.21.2
* spacecmd-4.3.23-150000.3.104.2
* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)
* golang-github-QubitProducts-exporter_exporter-0.4.0-150000.1.18.3
* golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.17.2
* prometheus-postgres_exporter-0.10.1-150000.1.14.3
* golang-github-lusitaniae-apache_exporter-debuginfo-1.0.0-150000.1.17.2
* prometheus-blackbox_exporter-0.24.0-150000.1.23.3
* openSUSE Leap 15.5 (noarch)
* supportutils-plugin-susemanager-client-4.3.3-150000.3.21.2
* spacecmd-4.3.23-150000.3.104.2
* SUSE Manager Client Tools for SLE 15 (aarch64...
Read the Full Advisory* #1204501
* #1208046
* #1208270
* #1208298
* #1208692
* #1211525
* #1213880
* MSQA-699
* PED-5405
* PED-5406
## References:
* https://www.suse.com/security/cve/CVE-2022-32149.html
* https://www.suse.com/security/cve/CVE-2022-41723.html
* https://www.suse.com/security/cve/CVE-2022-46146.html
* https://www.suse.com/security/cve/CVE-2023-29409.html
* https://bugzilla.suse.com/show_bug.cgi?id=1204501
* https://bugzilla.suse.com/show_bug.cgi?id=1208046
* https://bugzilla.suse.com/show_bug.cgi?id=1208270
* https://bugzilla.suse.com/show_bug.cgi?id=1208298
* https://bugzilla.suse.com/show_bug.cgi?id=1208692
* https://bugzilla.suse.com/show_bug.cgi?id=1211525
* https://bugzilla.suse.com/show_bug.cgi?id=1213880
*
*
*
Get the latest Linux and open source security news straight to your inbox.