Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 202404:15254-1 Moderate: Directory Traversal Security Issues

suse
Calendar Grey May 6, 2024
Dist Suse Esm H88
SUSE Manager Client Tools enhancement tackles vulnerabilities in directory traversal with crucial improvements. Prioritize security and knowledge!
* bsc#1211649 * bsc#1211888 * bsc#1216850 * bsc#1218482 * bsc#1219001

Summary

## This update fixes the following issues: salt: * Prevent directory traversal when creating syndic cache directory on the master (CVE-2024-22231, bsc#1219430) * Prevent directory traversal attacks in the master's serve_file method (CVE-2024-22232, bsc#1219431) * Convert oscap output to UTF-8 * Make Salt compatible with Python 3.11 * Ignore non-ascii chars in oscap output (bsc#1219001) * Fix detected issues in Salt tests when running on VMs * Make importing seco.range thread safe (bsc#1211649) * Fix problematic tests and allow smooth tests executions on containers * Discover Ansible playbook files as " _.yml " or "_.yaml" files (bsc#1211888) * Provide user(salt)/group(salt) capabilities for RPM 4.19 * Extend dependencies for python3-salt-testsuite and python3-salt packages

References

* bsc#1211649

* bsc#1211888

* bsc#1216850

* bsc#1218482

* bsc#1219001

* bsc#1219430

* bsc#1219431

* jsc#ECO-3319

* jsc#MSQA-760

Cross-

* CVE-2024-22231

* CVE-2024-22232

CVSS scores:

* CVE-2024-22231 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

* CVE-2024-22232 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected Products:

* SUSE Manager Client Tools for Ubuntu 20.04 2004

An update that solves two vulnerabilities, contains two features and has five

security fixes can now be installed.

##

* https://www.suse.com/security/cve/CVE-2024-22231.html

* https://www.suse.com/security/cve/CVE-2024-22232.html

* https://bugzilla.suse.com/show_bug.cgi?id=1211649

* https://bugzilla.suse.com/show_bug.cgi?id=1211888

Announcement ID: SUSE-SU-202404:15254-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here