Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2024:1517-1 Important: Salt Bundle Directory Traversal Issues

suse
Calendar Grey May 6, 2024
Dist Suse Esm H88
SUSE Manager Salt Bundle security bulletin issued to tackle critical vulnerabilities. Ensure your systems are protected with essential updates.
* bsc#1211649 * bsc#1211888 * bsc#1216850 * bsc#1218482 * bsc#1219001

Summary

## This update fixes the following issues: venv-salt-minion: * Security issues fixed: * CVE-2024-22231: Prevent directory traversal when creating syndic cache directory on the master (bsc#1219430) * CVE-2024-22232: Prevent directory traversal attacks in the master's serve_file method (bsc#1219431) * Bugs fixed: * Convert oscap output to UTF-8 * Make Salt compatible with Python 3.11 * Ignore non-ascii chars in oscap output (bsc#1219001) * Fix detected issues in Salt tests when running on VMs * Make importing seco.range thread safe (bsc#1211649) * Fix problematic tests and allow smooth tests executions on containers * Discover Ansible playbook files as " _.yml " or "_.yaml" files (bsc#1211888) * Prevent exceptions with fileserver.update when called via state (bsc#1218482)

References

* bsc#1211649

* bsc#1211888

* bsc#1216850

* bsc#1218482

* bsc#1219001

* bsc#1219430

* bsc#1219431

* jsc#MSQA-760

Cross-

* CVE-2024-22231

* CVE-2024-22232

CVSS scores:

* CVE-2024-22231 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

* CVE-2024-22232 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected Products:

* SUSE Linux Enterprise Desktop 12

* SUSE Linux Enterprise Desktop 12 SP1

* SUSE Linux Enterprise Desktop 12 SP2

* SUSE Linux Enterprise Desktop 12 SP3

* SUSE Linux Enterprise Desktop 12 SP4

* SUSE Linux Enterprise High Performance Computing 12 SP2

* SUSE Linux Enterprise High Performance Computing 12 SP3

* SUSE Linux Enterprise High Performance Computing 12 SP4

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:1517-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here