Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2022:0310-1 Moderate: Authentication Bypass And Path Traversal Fixes

suse
Calendar Grey February 2, 2022
Dist Suse Esm H88
Recent SUSE security patch addresses two vulnerabilities within SUSE Manager Tools, strengthening overall product security with essential updates.
An update that solves two vulnerabilities and has four fixes is now available

Summary

This update fixes the following issues: grafana: - Update to version 7.5.12: * Fix markdown path traversal (#42969, bsc#1193688, CVE-2021-43813) - Recreate tarballs using the makefile to update the npm and go modules required - Update to version 7.5.11: * Fix Snapshot authentication bypass (bsc#1191454, CVE-2021-39226) * Fix certs issue (#40002) * Release v7.5.11 (#124) * Fix static path matching issue in macaron * OAuth: add docs for disableAutoLogin param (#38752) (#38894) * Fix #747; remove 'other variables'. (#37866) (#37878) * Update alert docs (#33658) (#33659) * [7.5.x] Docs: added documentation for the "prepare time series"-transformation. (#36836) * cherry picked dc5778c303ca555b70e8ca8c28e95997e26ecfc1 (#36813) * "Release: Updated versions in package to 7.5.10" (#36792)

References

#1173103 #1191285 #1191454 #1192487 #1193600

#1193688

Cross- CVE-2021-39226 CVE-2021-43813

CVSS scores:

CVE-2021-39226 (NVD) : 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVE-2021-39226 (SUSE): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVE-2021-43813 (NVD) : 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVE-2021-43813 (SUSE): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products:

SUSE Manager Tools 12-BETA

https://www.suse.com/security/cve/CVE-2021-39226.html

https://www.suse.com/security/cve/CVE-2021-43813.html

https://bugzilla.suse.com/1173103

https://bugzilla.suse.com/1191285

https://bugzilla.suse.com/1191454

https://bugzilla.suse.com/1192487

https://bugzilla.suse.com/1193600

Announcement ID: SUSE-SU-2022:0310-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here