Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2020:0684-1 Moderate: Salt User Escalation and Code Execution

suse
Calendar Grey March 13, 2020
Dist Suse Esm H88
A new version has been released for salt that resolves two problems and offers eight improvements for SUSE Linux customers.
An update that solves two vulnerabilities and has 7 fixes is now available

Summary

This update for salt fixes the following issues: - Avoid possible user escalation upgrading salt-master (bsc#1157465) (CVE-2019-18897) - Fix unit tests failures in test_batch_async tests - Batch Async: Handle exceptions, properly unregister and close instances after running async batching to avoid CPU starvation of the MWorkers (bsc#1162327) - RHEL/CentOS 8 uses platform-python instead of python3 - New configuration option for selection of grains in the minion start event. - Fix 'os_family' grain for Astra Linux Common Edition - Fix for salt-api NET API where unauthenticated attacker could run arbitrary code (CVE-2019-17361) (bsc#1162504) - Adds disabled parameter to mod_repo in aptpkg module Move token with atomic operation Bad API token files get deleted (bsc#1160931)

References

#1135656 #1153611 #1157465 #1158940 #1159118

#1160931 #1162327 #1162504 #1165425

Cross- CVE-2019-17361 CVE-2019-18897

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15-SP1

SUSE Linux Enterprise Module for Python2 15-SP1

SUSE Linux Enterprise Module for Basesystem 15-SP1

https://www.suse.com/security/cve/CVE-2019-17361.html

https://www.suse.com/security/cve/CVE-2019-18897.html

https://bugzilla.suse.com/1135656

https://bugzilla.suse.com/1153611

https://bugzilla.suse.com/1157465

https://bugzilla.suse.com/1158940

https://bugzilla.suse.com/1159118

https://bugzilla.suse.com/1160931

https://bugzilla.suse.com/1162327

https://bugzilla.suse.com/1162504

https://bugzilla.suse.com/1165425

Announcement ID: SUSE-SU-2020:0684-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here