Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update fixes the following issues: cobbler: - Fixed modify_setting test to complete successfully hub-xmlrpc-api: - Use rpm systemd macro to restart service in replace of systemctl patterns-suse-manager: - Virtualization-host-formula was renamed to virtualization-formulas py26-compat-salt: - Exclude the full path of a download URL to prevent injection of malicious code (bsc#1190265, CVE-2021-21996) py26-compat-tornado: - Added compatibility to Enterprise Linux 8 py27-compat-salt: - Fix the regression of docker_container state module - Support querying for JSON data in external sql pillar - Exclude the full path of a download URL to prevent injection of malicious code (bsc#1190265, CVE-2021-21996) - Fix wrong relative paths resolution with Jinja renderer when importing subdirectories spacecmd:
#1171520 #1181223 #1187572 #1187998 #1188315
#1188977 #1189260 #1189422 #1189609 #1189799
#1189818 #1189933 #1190040 #1190123 #1190151
#1190164 #1190166 #1190265 #1190275 #1190276
#1190300 #1190396 #1190405 #1190455 #1190512
#1190602 #1190751 #1190820 #1191123 #1191139
#1191348 #1191551 #1191898 PM-2644 SUMA-61
Cross- CVE-2021-21996 CVE-2021-40348
CVSS scores:
CVE-2021-21996 (SUSE): 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVE-2021-40348 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
SUSE Linux Enterprise Module for SUSE Manager Server 4.2
https://www.suse.com/security/cve/CVE-2021-21996.html
https://www.suse.com/security/cve/CVE-2021-40348.html
https://bugzilla.suse.com/1171520
https://bugzilla.suse.com/1181223
Get the latest Linux and open source security news straight to your inbox.