Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2024:1521-1 Moderate: Directory Traversal Protection in Salt Bundle

suse
Calendar Grey May 6, 2024
Dist Suse Esm H88
Essential security patches for SUSE Manager Salt Package rectify directory traversal vulnerabilities and provide enhanced installation guidelines.
* bsc#1211649 * bsc#1211888 * bsc#1216850 * bsc#1218482 * bsc#1219001

Summary

## This update fixes the following issues: venv-salt-minion: * CVE-2024-22231: Prevent directory traversal when creating syndic cache directory on the master (bsc#1219430) * CVE-2024-22232: Prevent directory traversal attacks in the master's serve_file method (bsc#1219431) * Convert oscap output to UTF-8 * Make Salt compatible with Python 3.11 * Ignore non-ascii chars in oscap output (bsc#1219001) * Fix detected issues in Salt tests when running on VMs * Make importing seco.range thread safe (bsc#1211649) * Fix problematic tests and allow smooth tests executions on containers * Discover Ansible playbook files as " _.yml " or "_.yaml" files (bsc#1211888) * Prevent exceptions with fileserver.update when called via state (bsc#1218482) * Improve pip target override condition with VENV_PIP_TARGET environment

References

* bsc#1211649

* bsc#1211888

* bsc#1216850

* bsc#1218482

* bsc#1219001

* bsc#1219430

* bsc#1219431

* jsc#MSQA-760

Cross-

* CVE-2024-22231

* CVE-2024-22232

CVSS scores:

* CVE-2024-22231 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

* CVE-2024-22232 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected Products:

* SUSE Manager Client Tools for Debian 11

An update that solves two vulnerabilities, contains one feature and has five

security fixes can now be installed.

##

* https://www.suse.com/security/cve/CVE-2024-22231.html

* https://www.suse.com/security/cve/CVE-2024-22232.html

* https://bugzilla.suse.com/show_bug.cgi?id=1211649

* https://bugzilla.suse.com/show_bug.cgi?id=1211888

* https://bugzilla.suse.com/show_bug.cgi?id=1216850

Announcement ID: SUSE-SU-2024:1521-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here