Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2022:0310-1 Moderate: Authentication Bypass And Path Traversal Fixes

suse
Calendar Grey February 2, 2022
Scroller Suse
Recent SUSE security patch addresses two vulnerabilities within SUSE Manager Tools, strengthening overall product security with essential updates.
An update that solves two vulnerabilities and has four fixes is now available

Summary

This update fixes the following issues: grafana: - Update to version 7.5.12: * Fix markdown path traversal (#42969, bsc#1193688, CVE-2021-43813) - Recreate tarballs using the makefile to update the npm and go modules required - Update to version 7.5.11: * Fix Snapshot authentication bypass (bsc#1191454, CVE-2021-39226) * Fix certs issue (#40002) * Release v7.5.11 (#124) * Fix static path matching issue in macaron * OAuth: add docs for disableAutoLogin param (#38752) (#38894) * Fix #747; remove 'other variables'. (#37866) (#37878) * Update alert docs (#33658) (#33659) * [7.5.x] Docs: added documentation for the "prepare time series"-transformation. (#36836) * cherry picked dc5778c303ca555b70e8ca8c28e95997e26ecfc1 (#36813) * "Release: Updated versions in package to 7.5.10" (#36792)

References

#1173103 #1191285 #1191454 #1192487 #1193600

#1193688

Cross- CVE-2021-39226 CVE-2021-43813

CVSS scores:

CVE-2021-39226 (NVD) : 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVE-2021-39226 (SUSE): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVE-2021-43813 (NVD) : 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVE-2021-43813 (SUSE): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products:

SUSE Manager Tools 12-BETA

https://www.suse.com/security/cve/CVE-2021-39226.html

https://www.suse.com/security/cve/CVE-2021-43813.html

https://bugzilla.suse.com/1173103

https://bugzilla.suse.com/1191285

https://bugzilla.suse.com/1191454

https://bugzilla.suse.com/1192487

https://bugzilla.suse.com/1193600

Announcement ID: SUSE-SU-2022:0310-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.