FlawAtlas
Search the atlas
SUSE-SU-2023:0812-1 Not scored

Security update for SUSE Manager Client Tools

This update fixes the following issues: dracut-saltboot: - Update to verion 0.1.1674034019.a93ff61 * Install copied wicked config as client.xml (bsc#1205599) - Update to version 0.1.1673279145.e7616bd grafana: - CVE-2022-46146: Fix basic authentication bypass by updating the exporter toolkit to version 0.7.3 (bsc#1208065,) - CVE-2022-41723: Require Go 1.19 or newer (bsc#1208293) - Update to version 8.5.20: * CVE-2022-23552: Security: SVG: Add dompurify preprocessor step (bsc#1207749) * CVE-2022-39324: Security: Snapshots: Fix originalUrl spoof security issue (bsc#1207750) * Security: Omit error from http response * Bug fix: Email and username trimming and invitation validation spacecmd: - Version 4.3.19-1 * Fix spacecmd not showing any output for softwarechannel_diff and softwarechannel_errata_diff (bsc#1207352) * Prevent string api parameters to be parsed as dates if not in ISO-8601 format (bsc#1205759) spacewalk-client-tools: - Version 4.3.15-1 * Update translation strings supportutils-plugin-salt: - Update to version 1.2.2 * Remove possible passwords from Salt configuration files (bsc#1201059) uyuni-proxy-systemd-services: - Version 4.3.8-1 * Allow using container images from different registry paths

Exploit probability Not scored
Published March 20, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7 supportutils-plugin-salt
SUSE:Enterprise Storage 7.1 supportutils-plugin-salt
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS supportutils-plugin-salt
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS supportutils-plugin-salt
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS supportutils-plugin-salt
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS supportutils-plugin-salt
SUSE:Linux Enterprise Module for Basesystem 15 SP4 supportutils-plugin-salt
SUSE:Linux Enterprise Real Time 15 SP3 supportutils-plugin-salt
SUSE:Linux Enterprise Server 15 SP1-LTSS supportutils-plugin-salt
SUSE:Linux Enterprise Server 15 SP2-LTSS supportutils-plugin-salt
SUSE:Linux Enterprise Server 15 SP3-LTSS supportutils-plugin-salt
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 supportutils-plugin-salt
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 supportutils-plugin-salt
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 supportutils-plugin-salt
SUSE:Manager Client Tools 15 dracut-saltboot
SUSE:Manager Client Tools 15 grafana
SUSE:Manager Client Tools 15 spacecmd
SUSE:Manager Client Tools 15 spacewalk-client-tools
SUSE:Manager Client Tools 15 supportutils-plugin-salt
SUSE:Manager Client Tools 15 uyuni-proxy-systemd-services
SUSE:Manager Client Tools for SLE Micro 5 dracut-saltboot
SUSE:Manager Client Tools for SLE Micro 5 uyuni-proxy-systemd-services
SUSE:Manager Proxy 4.2 supportutils-plugin-salt
SUSE:Manager Server 4.2 supportutils-plugin-salt
openSUSE:Leap 15.4 dracut-saltboot
openSUSE:Leap 15.4 spacecmd
openSUSE:Leap 15.4 supportutils-plugin-salt

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:0812-1

This update fixes the following issues: dracut-saltboot: - Update to verion 0.1.1674034019.a93ff61 * Install copied wicked config as client.xml (bsc#1205599) - Update to version 0.1.1673279145.e7616bd grafana: - CVE-2022-46146: Fix basic authentication bypass by updating the exporter toolkit to version 0.7.3 (bsc#1208065,) - CVE-2022-41723: Require Go 1.19 or newer (bsc#1208293) - Update to version 8.5.20: * CVE-2022-23552: Security: SVG: Add dompurify preprocessor step (bsc#1207749) * CVE-2022-39324: Security: Snapshots: Fix originalUrl spoof security issue (bsc#1207750) * Security: Omit error from http response * Bug fix: Email and username trimming and invitation validation spacecmd: - Version 4.3.19-1 * Fix spacecmd not showing any output for softwarechannel_diff and softwarechannel_errata_diff (bsc#1207352) * Prevent string api parameters to be parsed as dates if not in ISO-8601 format (bsc#1205759) spacewalk-client-tools: - Version 4.3.15-1 * Update translation strings supportutils-plugin-salt: - Update to version 1.2.2 * Remove possible passwords from Salt configuration files (bsc#1201059) uyuni-proxy-systemd-services: - Version 4.3.8-1 * Allow using container images from different registry paths

View original source

05 / REFERENCES

Further evidence