FlawAtlas
Search the atlas
SUSE-SU-2022:3178-1 Not scored

Important security update for SUSE Manager Client Tools

This update fixes the following issues: ansible: - Update to version 2.9.27 (jsc#SLE-23631, jsc#SLE-24133) * CVE-2021-3620 ansible-connection module discloses sensitive info in traceback error message (in 2.9.27) (bsc#1187725) * CVE-2021-3583 Template Injection through yaml multi-line strings with ansible facts used in template. (in 2.9.23) (bsc#1188061) * ansible module nmcli is broken in ansible 2.9.13 (in 2.9.15) (bsc#1176460) - Update to 2.9.22: * CVE-2021-3447 (bsc#1183684) multiple modules expose secured values * CVE-2021-20228 (bsc#1181935) basic.py no_log with fallback option * CVE-2021-20191 (bsc#1181119) multiple collections exposes secured values * CVE-2021-20180 (bsc#1180942) bitbucket_pipeline_variable exposes sensitive values * CVE-2021-20178 (bsc#1180816) user data leak in snmp_facts module dracut-saltboot: - Require e2fsprogs (bsc#1202614) - Update to version 0.1.1657643023.0d694ce * Update dracut-saltboot dependencies (bsc#1200970) * Fix network loading when ipappend is used in pxe config * Add new information messages golang-github-QubitProducts-exporter_exporter: - Remove license file from %doc mgr-daemon: - Version 4.3.5-1 * Update translation strings mgr-virtualization: - Version 4.3.6-1 * Report all VMs in poller, not only running ones (bsc#1199528) prometheus-blackbox_exporter: - Exclude s390 arch python-hwdata: - Declare the LICENSE file as license and not doc spacecmd: - Version 4.3.14-1 * Fix missing argument on system_listmigrationtargets (bsc#1201003) * Show correct help on calling kickstart_importjson with no arguments * Fix tracebacks on spacecmd kickstart_export (bsc#1200591) * Change proxy container config default filename to end with tar.gz * Update translation strings spacewalk-client-tools: - Version 4.3.11-1 * Update translation strings uyuni-common-libs: - Version 4.3.5-1 * Fix reposync issue about 'rpm.hdr' object has no attribute 'get' uyuni-proxy-systemd-services: - Version 4.3.6-1 * Expose port 80 (bsc#1200142) * Use volumes rather than bind mounts * TFTPD to listen on udp port (bsc#1200968) * Add TAG variable in configuration * Fix containers namespaces in configuration zypp-plugin-spacewalk: - 1.0.13 * Log in before listing channels. (bsc#1197963, bsc#1193585)

Exploit probability Not scored
Published September 8, 2022
Required by Not available
Last source change May 2, 2025

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 15-LTSS golang-github-prometheus-node_exporter
openSUSE:Leap 15.3 dracut-saltboot
SUSE:Manager Client Tools 15 uyuni-proxy-systemd-services
SUSE:Manager Client Tools 15 prometheus-blackbox_exporter
SUSE:Manager Proxy Module 4.3 zypp-plugin-spacewalk
SUSE:Manager Proxy Module 4.1 zypp-plugin-spacewalk
SUSE:Manager Server Module 4.2 golang-github-QubitProducts-exporter_exporter
SUSE:Manager Server Module 4.3 python-hwdata
SUSE:Manager Server Module 4.1 python-hwdata
SUSE:Manager Client Tools 15 mgr-virtualization
SUSE:Manager Proxy Module 4.2 python-hwdata
SUSE:Manager Client Tools 15 ansible
openSUSE:Leap 15.3 golang-github-QubitProducts-exporter_exporter
SUSE:Manager Client Tools 15 mgr-daemon
SUSE:Manager Client Tools 15 dracut-saltboot
openSUSE:Leap 15.4 wire
SUSE:Manager Client Tools 15 uyuni-common-libs
SUSE:Manager Proxy Module 4.1 python-hwdata
SUSE:Manager Client Tools 15 golang-github-QubitProducts-exporter_exporter
SUSE:Manager Proxy Module 4.2 golang-github-QubitProducts-exporter_exporter
SUSE:Manager Server Module 4.2 python-hwdata
SUSE:Manager Proxy Module 4.3 golang-github-QubitProducts-exporter_exporter
SUSE:Manager Proxy Module 4.3 ansible
SUSE:Manager Proxy Module 4.3 python-hwdata
openSUSE:Leap 15.4 prometheus-blackbox_exporter
SUSE:Linux Enterprise Server for SAP Applications 15 golang-github-prometheus-node_exporter
SUSE:Manager Client Tools 15 spacecmd
SUSE:Manager Proxy Module 4.3 prometheus-blackbox_exporter
openSUSE:Leap 15.4 dracut-saltboot
SUSE:Manager Client Tools 15 python-hwdata
SUSE:Manager Proxy Module 4.2 ansible
openSUSE:Leap 15.3 spacecmd
openSUSE:Leap 15.4 ansible
SUSE:Linux Enterprise High Performance Computing 15-LTSS golang-github-prometheus-node_exporter
openSUSE:Leap 15.4 golang-github-QubitProducts-exporter_exporter
SUSE:Linux Enterprise High Performance Computing 15-ESPOS golang-github-prometheus-node_exporter
openSUSE:Leap 15.4 python-hwdata
SUSE:Manager Proxy Module 4.2 prometheus-blackbox_exporter
openSUSE:Leap 15.4 spacecmd
SUSE:Manager Proxy Module 4.2 zypp-plugin-spacewalk
SUSE:Manager Client Tools 15 zypp-plugin-spacewalk
openSUSE:Leap 15.3 ansible
SUSE:Manager Server Module 4.3 golang-github-QubitProducts-exporter_exporter
openSUSE:Leap 15.3 python-hwdata
SUSE:Manager Client Tools 15 spacewalk-client-tools

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2022:3178-1

This update fixes the following issues: ansible: - Update to version 2.9.27 (jsc#SLE-23631, jsc#SLE-24133) * CVE-2021-3620 ansible-connection module discloses sensitive info in traceback error message (in 2.9.27) (bsc#1187725) * CVE-2021-3583 Template Injection through yaml multi-line strings with ansible facts used in template. (in 2.9.23) (bsc#1188061) * ansible module nmcli is broken in ansible 2.9.13 (in 2.9.15) (bsc#1176460) - Update to 2.9.22: * CVE-2021-3447 (bsc#1183684) multiple modules expose secured values * CVE-2021-20228 (bsc#1181935) basic.py no_log with fallback option * CVE-2021-20191 (bsc#1181119) multiple collections exposes secured values * CVE-2021-20180 (bsc#1180942) bitbucket_pipeline_variable exposes sensitive values * CVE-2021-20178 (bsc#1180816) user data leak in snmp_facts module dracut-saltboot: - Require e2fsprogs (bsc#1202614) - Update to version 0.1.1657643023.0d694ce * Update dracut-saltboot dependencies (bsc#1200970) * Fix network loading when ipappend is used in pxe config * Add new information messages golang-github-QubitProducts-exporter_exporter: - Remove license file from %doc mgr-daemon: - Version 4.3.5-1 * Update translation strings mgr-virtualization: - Version 4.3.6-1 * Report all VMs in poller, not only running ones (bsc#1199528) prometheus-blackbox_exporter: - Exclude s390 arch python-hwdata: - Declare the LICENSE file as license and not doc spacecmd: - Version 4.3.14-1 * Fix missing argument on system_listmigrationtargets (bsc#1201003) * Show correct help on calling kickstart_importjson with no arguments * Fix tracebacks on spacecmd kickstart_export (bsc#1200591) * Change proxy container config default filename to end with tar.gz * Update translation strings spacewalk-client-tools: - Version 4.3.11-1 * Update translation strings uyuni-common-libs: - Version 4.3.5-1 * Fix reposync issue about 'rpm.hdr' object has no attribute 'get' uyuni-proxy-systemd-services: - Version 4.3.6-1 * Expose port 80 (bsc#1200142) * Use volumes rather than bind mounts * TFTPD to listen on udp port (bsc#1200968) * Add TAG variable in configuration * Fix containers namespaces in configuration zypp-plugin-spacewalk: - 1.0.13 * Log in before listing channels. (bsc#1197963, bsc#1193585)

View original source

05 / REFERENCES

Further evidence