Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2022:0510-1 Important Security Update For Cobbler Permissions

suse
Calendar Grey February 18, 2022
Dist Suse Esm H88
Cobbler Security Patch for SUSE Linux resolves two major vulnerabilities concerning permission settings and template cleaning.
An update that solves two vulnerabilities and has 5 fixes is now available

Summary

This update for cobbler fixes the following issues: - CVE-2021-45083: Fixed unsafe permissions on sensitive files (bsc#1193671). - CVE-2021-45082: Fixed incomplete template sanitation (bsc#1193678). The following non-security bugs were fixed: - Fix issues with installation module logging and validation (bsc#1195918) - Move configuration files ownership to apache (bsc#1195906) - Remove hardcoded test credentials (bsc#1193673) - Prevent log pollution (bsc#1193675) - Missing sanity check on MongoDB configuration file (bsc#1193676) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for SUSE Manager Server 4.1:

References

#1193671 #1193673 #1193675 #1193676 #1193678

#1195906 #1195918

Cross- CVE-2021-45082 CVE-2021-45083

CVSS scores:

CVE-2021-45082 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2021-45083 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected Products:

SUSE Linux Enterprise Module for SUSE Manager Server 4.1

SUSE Manager Server 4.1

https://www.suse.com/security/cve/CVE-2021-45082.html

https://www.suse.com/security/cve/CVE-2021-45083.html

https://bugzilla.suse.com/1193671

https://bugzilla.suse.com/1193673

https://bugzilla.suse.com/1193675

https://bugzilla.suse.com/1193676

https://bugzilla.suse.com/1193678

https://bugzilla.suse.com/1195906

https://bugzilla.suse.com/1195918

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0510-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here