FlawAtlas
Search the atlas
SUSE-SU-2018:3862-1 Not scored

Security update for salt

This update for salt fixes the following issues: Security issues fixed: - CVE-2018-15750: Fixed directory traversal vulnerability in salt-api (bsc#1113698). - CVE-2018-15751: Fixed remote authentication bypass in salt-api(netapi) that allows to execute arbitrary commands (bsc#1113699). Non-security issues fixed: - Improved handling of LDAP group id. gid is no longer treated as a string, which could have lead to faulty group creations (bsc#1113784). - Fix async call to process manager (bsc#1110938). - Fixed OS arch detection when RPM is not installed (bsc#1114197).

Exploit probability Not scored
Published November 22, 2018
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Advanced Systems Management 12 salt
SUSE:Linux Enterprise Point of Sale 12 SP2 salt
SUSE:Manager Client Tools 12 salt
SUSE:Manager Proxy 3.0 salt
SUSE:Manager Proxy 3.1 salt
SUSE:Manager Proxy 3.2 salt
SUSE:Manager Server 3.0 salt
SUSE:Manager Server 3.1 salt
SUSE:Manager Server 3.2 salt

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2018:3862-1

This update for salt fixes the following issues: Security issues fixed: - CVE-2018-15750: Fixed directory traversal vulnerability in salt-api (bsc#1113698). - CVE-2018-15751: Fixed remote authentication bypass in salt-api(netapi) that allows to execute arbitrary commands (bsc#1113699). Non-security issues fixed: - Improved handling of LDAP group id. gid is no longer treated as a string, which could have lead to faulty group creations (bsc#1113784). - Fix async call to process manager (bsc#1110938). - Fixed OS arch detection when RPM is not installed (bsc#1114197).

View original source

05 / REFERENCES

Further evidence