Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE: 2022:2139-1 Important: Golang Alertmanager DoS Issue Fixed

suse
Calendar Grey June 20, 2022
Dist Suse Esm H88
The latest security patch for golang-github-prometheus-alertmanager tackles critical vulnerabilities and improves overall capabilities of the application.
An update that solves one vulnerability, contains one feature and has one errata is now available

Summary

This update for golang-github-prometheus-alertmanager fixes the following issues: Update golang-github-prometheus-alertmanager from version 0.21.0 to version 0.23.0 (bsc#1196338, jsc#SLE-24077) - CVE-2022-21698: Denial of service using InstrumentHandlerCounter - Update vendor tarball with prometheus/client_golang 1.11.1 - Update required Go version to 1.16 - Use %autosetup macro - Update to version 0.23.0: * Release 0.23.0 * Release 0.23.0-rc.0 * amtool: Detect version drift and warn users (#2672) * Add ability to skip TLS verification for amtool (#2663) * Fix empty isEqual in amtool. (#2668) * Fix main tests (#2670) * cli: add new template render command (#2538) * OpsGenie: refer to alert instead of incident (#2609) * Docs: target_match and source_match are DEPRECATED (#2665)

References

#1181400 #1196338 SLE-24077

Cross- CVE-2022-21698

CVSS scores:

CVE-2022-21698 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-21698 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

SUSE Enterprise Storage 6

SUSE Linux Enterprise Module for SUSE Manager Proxy 4.1

SUSE Linux Enterprise Module for SUSE Manager Proxy 4.2

SUSE Linux Enterprise Module for SUSE Manager Proxy 4.3

SUSE Manager Proxy 4.1

SUSE Manager Proxy 4.2

SUSE Manager Proxy 4.3

SUSE Manager Tools 15

openSUSE Leap 15.3

openSUSE Leap 15.4

https://www.suse.com/security/cve/CVE-2022-21698.html

https://bugzilla.suse.com/1181400

https://bugzilla.suse.com/1196338

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:2139-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here