Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

openSUSE Backports SLE-15-SP5: 2024:0382-1 important: API security fix

opensuse
Calendar Grey November 28, 2024
Dist Opensuse Esm H88
A noteworthy release for Fedora addresses a critical bug while introducing several improvements for the Ansible automation framework.
An update that solves one vulnerability and has 10 fixes is now available

Description

This update for cobbler fixes the following issues:

Update to 3.3.7:

* Security: Fix issue that allowed anyone to connect to the API as admin

(CVE-2024-47533, boo#1231332)

* bind - Fix bug that prevents cname entries from being generated

successfully

* Fix build on RHEL9 based distributions (fence-agents-all split)

* Fix for Windows systems

* Docs: Add missing dependencies for source installation

* Fix issue that prevented systems from being synced when the profile

was edited

Update to 3.3.6:

* Upstream all openSUSE specific patches that were maintained in Git

* Fix rename of items that had uppercase letters

* Skip inconsistent collections instead of crashing the daemon

- Update to 3.3.5:

* Added collection indicies for UUID's, MAC's, IP addresses and

hostnames boo#1219933

* Re-added to_dict() caching

* Added lazy loading for the daemon (off by default)

- Update to 3.3.4:

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2024-382=1

Package List

- openSUSE Backports SLE-15-SP5 (noarch):

cobbler-3.3.7-bp155.2.3.2

cobbler-tests-3.3.7-bp155.2.3.2

cobbler-tests-containers-3.3.7-bp155.2.3.2

References

https://www.suse.com/security/cve/CVE-2024-47533.html

https://bugzilla.suse.com/1203478

https://bugzilla.suse.com/1204900

https://bugzilla.suse.com/1205489

https://bugzilla.suse.com/1205749

https://bugzilla.suse.com/1206060

https://bugzilla.suse.com/1206160

https://bugzilla.suse.com/1206520

https://bugzilla.suse.com/1207595

https://bugzilla.suse.com/1209149

https://bugzilla.suse.com/1219933

https://bugzilla.suse.com/1231332

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2024:0382-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP5 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here