Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2022:1528-1 Important: MiTM Security Fixes for Client Tools

suse
Calendar Grey May 4, 2022
Dist Suse Esm H88
Critical patch resolves Man-in-the-Middle vulnerabilities in SUSE Manager Client Applications, highlighting key update information.
An update that fixes four vulnerabilities is now available

Summary

This update fixes the following issues: Security fixes for salt (bsc#1197417): - CVE-2022-22935: Sign authentication replies to prevent MiTM. - CVE-2022-22934: Sign pillar data to prevent MiTM attacks. - CVE-2022-22936: Prevent job and fileserver replays. - CVE-2022-22941: Fixed targeting bug, especially visible when using syndic and user auth. Other non security fixes: salt: - Prevent data pollution between actions processed at the same time (bsc#1197637) - Fix regression preventing bootstrapping new clients caused by redundant dependency on psutil (bsc#1197533) - Fixes for Python 3.10 - Fix salt-ssh opts poisoning (bsc#1197637) spacecmd: - Version 4.3.10-1 * parse boolean paramaters correctly (bsc#1197689) * Add parameter to set containerized proxy SSH port Patch Instructions:

References

#1197417 #1197533 #1197637 #1197689

Cross- CVE-2022-22934 CVE-2022-22935 CVE-2022-22936

CVE-2022-22941

CVSS scores:

CVE-2022-22934 (NVD) : 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-22934 (SUSE): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-22935 (NVD) : 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

CVE-2022-22935 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-22936 (NVD) : 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-22936 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-22941 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2022-22941 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

SUSE Manager Debian 10-CLIENT-TOOLS-BETA

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:1528-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here