Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

openSUSE: 2024:0370-1 critical update for cobbler API access issue

opensuse
Calendar Grey November 21, 2024
Dist Opensuse Esm H88
An important security patch for cobbler fixes an issue related to API accessibility in openSUSE environments.
An update that fixes one vulnerability is now available

Description

This update for cobbler fixes the following issues:

Update to 3.3.7

* Security: Fix issue that allowed anyone to connect to the API as admin

(CVE-2024-47533, boo#1231332)

* bind - Fix bug that prevents cname entries from being generated

successfully

* Fix build on RHEL9 based distributions (fence-agents-all split)

* Fix for Windows systems

* Docs: Add missing dependencies for source installation

* Fix issue that prevented systems from being synced when the profile was

edited

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2024-370=1

Package List

- openSUSE Backports SLE-15-SP6 (noarch):

cobbler-3.3.7-bp156.2.6.1

cobbler-tests-3.3.7-bp156.2.6.1

cobbler-tests-containers-3.3.7-bp156.2.6.1

References

https://www.suse.com/security/cve/CVE-2024-47533.html

https://bugzilla.suse.com/1231332

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2024:0370-1
Rating: critical
Affected Products: openSUSE Backports SLE-15-SP6 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here