Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2018:3073-1 Moderate: kubernetes-salt File Access Issue

suse
Calendar Grey October 8, 2018
Dist Suse Esm H88
SUSE Security Patch resolves several vulnerabilities in salt-kubernetes and velum under advisory ID SUSE-SU-2018:3074-1.
An update that solves one vulnerability and has two fixes is now available

Summary

This update for rubygem-sprockets to version 3.7.2 and velum fixes the following issues: This security issue was fixed in rubygem-sprockets: - CVE-2018-3760: Specially crafted requests could have been be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production (bsc#1098369) These non-security issues were fixed in velum: - Fix external auth group mapping for group attr name. (bsc#1109320) - Add configmap from pillar data to dex ldap connectors (fate#324601) - Backport of LDAP external auth feature (fate#324601) - Allow the user to upload a certificate via file (bsc#1097753) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1097753 #1098369 #1109320

Cross- CVE-2018-3760

Affected Products:

SUSE CaaS Platform 3.0

https://www.suse.com/security/cve/CVE-2018-3760.html

https://bugzilla.suse.com/1097753

https://bugzilla.suse.com/1098369

https://bugzilla.suse.com/1109320

Announcement ID: SUSE-SU-2018:3073-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here