This update fixes the following issues: venv-salt-minion: - Add support for gpgautoimport in zypperpkg module - Update Salt to work with Jinja >= and <= 3.1.0 (bsc#1198744) - Fix salt.states.file.managed() for follow_symlinks=True and test=True (bsc#1199372) - Make Salt 3004 compatible with pyzmq >= 23.0.0 (bsc#1201082) - Add support for name, pkgs and diff_attr parameters to upgrade function for zypper and yum (bsc#1198489) - Fix possible errors on running post install script if semanage is present on the system, but SELinux is not configured - Remove unused imports in the venv wrappers - Set VENV_PIP_TARGET to /var/lib/venv-salt-minion/local to force PIP use it as the destination to install modules - Fix ownership of salt thin directory when using the Salt Bundle
#1195895 #1197288 #1198489 #1198744 #1199372
#1200566 #1201082
Cross- CVE-2022-22967
CVSS scores:
CVE-2022-22967 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2022-22967 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
SUSE Manager Ubuntu 18.04-CLIENT-TOOLS
https://www.suse.com/security/cve/CVE-2022-22967.html
https://bugzilla.suse.com/1195895
https://bugzilla.suse.com/1197288
https://bugzilla.suse.com/1198489
https://bugzilla.suse.com/1198744
https://bugzilla.suse.com/1199372
https://bugzilla.suse.com/1200566
https://bugzilla.suse.com/1201082
Get the latest Linux and open source security news straight to your inbox.