Security update for SUSE Manager 4.0
This security update for SUSE Manager 4.0 provides the following fixes: py26-compat-salt: - Properly validate eauth credentials and tokens on SSH calls made by Salt API (bsc#1178319, bsc#1178362, bsc#1178361, CVE-2020-25592, CVE-2020-17490, CVE-2020-16846) spacewalk-java: - Use correct eauth module and credentials for Salt SSH calls. (bsc#1178319, CVE-2020-25592)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This security update for SUSE Manager 4.0 provides the following fixes: py26-compat-salt: - Properly validate eauth credentials and tokens on SSH calls made by Salt API (bsc#1178319, bsc#1178362, bsc#1178361, CVE-2020-25592, CVE-2020-17490, CVE-2020-16846) spacewalk-java: - Use correct eauth module and credentials for Salt SSH calls. (bsc#1178319, CVE-2020-25592)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1178319
- https://bugzilla.suse.com/1178361
- https://bugzilla.suse.com/1178362
- https://www.suse.com/security/cve/CVE-2020-16846
- https://www.suse.com/security/cve/CVE-2020-17490
- https://www.suse.com/security/cve/CVE-2020-25592
- https://www.suse.com/support/update/announcement/2020/suse-su-20203250-1/