Security update for SUSE Manager Client Tools
This update fixes the following issues: golang-github-lusitaniae-apache_exporter: - Security issues fixed: * CVE-2022-32149: Fix denial of service vulnerability (bsc#1204501) * CVE-2022-41723: Fix uncontrolled resource consumption (bsc#1208270) * CVE-2022-46146: Fix authentication bypass vulnarability (bsc#1208046) - Changes and bugs fixed: * Updated to 1.0.0 (jsc#PED-5405) + Improved flag parsing + Added support for custom headers * Changes from 0.13.1 + Fix panic caused by missing flagConfig options * Changes from 0.11.0 (jsc#SLE-24791) + Add TLS support + Switch to logger, please check --log.level and --log.format flags * Changes from 0.10.1 + Bugfix: Reset ProxyBalancer metrics on each scrape to remove stale data * Changes from 0.10.0 + Add Apache Proxy and other metrics * Changes from 0.8.0 + Change commandline flags + Add metrics: Apache version, request duration total * Changes from 0.7.0 + Handle OS TERM signals * Changes from 0.6.0 + Add option to override host name * Added support for Red Hat Enterprise Linux * Added AppArmor profile * Added sandboxing options to systemd service unit * Build using promu * Build with Go 1.19 * Exclude s390 architecture golang-github-prometheus-node_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. golang-github-QubitProducts-exporter_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. prometheus-postgres_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. scap-security-guide: - Updated to 0.1.69 (jsc#ECO-3319) - Introduce a JSON build manifest - Introduce a script to compare ComplianceAsCode versions - Introduce CCN profiles for Red Hat Enterprise Linux 9 - Map rules to components - products/anolis23: supports Anolis OS 23 - Render components to HTML - Store rendered control files - Test and use rules to components mapping - Use distributed product properties - Revert patch that breaks the SLE hardening (bsc#1213691) - Changes from 0.1.68 (jsc#ECO-3319) - Bump OL8 STIG version to V1R6 - Introduce a Product class, make the project work with it - Introduce Fedora and Firefox CaC profiles for common workstation users - OL7 DISA STIG v2r11 update - Publish rendered policy artifacts - Update ANSSI BP-028 to version 2.0 - Changes from 0.1.67 (jsc#ECO-3319) - Add utils/controlrefcheck.py - Red Hat Enterprise Linux 9 STIG Update Q1 2023 - Include warning for NetworkManager keyfiles in Red Hat Enterprise Linux 9 - OL7 stig v2r10 update - Bump version of OL8 STIG to V1R5 - Various enhancements to SLE profiles spacecmd: - Updated to 4.3.23-1 * Update translation strings
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: golang-github-lusitaniae-apache_exporter: - Security issues fixed: * CVE-2022-32149: Fix denial of service vulnerability (bsc#1204501) * CVE-2022-41723: Fix uncontrolled resource consumption (bsc#1208270) * CVE-2022-46146: Fix authentication bypass vulnarability (bsc#1208046) - Changes and bugs fixed: * Updated to 1.0.0 (jsc#PED-5405) + Improved flag parsing + Added support for custom headers * Changes from 0.13.1 + Fix panic caused by missing flagConfig options * Changes from 0.11.0 (jsc#SLE-24791) + Add TLS support + Switch to logger, please check --log.level and --log.format flags * Changes from 0.10.1 + Bugfix: Reset ProxyBalancer metrics on each scrape to remove stale data * Changes from 0.10.0 + Add Apache Proxy and other metrics * Changes from 0.8.0 + Change commandline flags + Add metrics: Apache version, request duration total * Changes from 0.7.0 + Handle OS TERM signals * Changes from 0.6.0 + Add option to override host name * Added support for Red Hat Enterprise Linux * Added AppArmor profile * Added sandboxing options to systemd service unit * Build using promu * Build with Go 1.19 * Exclude s390 architecture golang-github-prometheus-node_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. golang-github-QubitProducts-exporter_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. prometheus-postgres_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. scap-security-guide: - Updated to 0.1.69 (jsc#ECO-3319) - Introduce a JSON build manifest - Introduce a script to compare ComplianceAsCode versions - Introduce CCN profiles for Red Hat Enterprise Linux 9 - Map rules to components - products/anolis23: supports Anolis OS 23 - Render components to HTML - Store rendered control files - Test and use rules to components mapping - Use distributed product properties - Revert patch that breaks the SLE hardening (bsc#1213691) - Changes from 0.1.68 (jsc#ECO-3319) - Bump OL8 STIG version to V1R6 - Introduce a Product class, make the project work with it - Introduce Fedora and Firefox CaC profiles for common workstation users - OL7 DISA STIG v2r11 update - Publish rendered policy artifacts - Update ANSSI BP-028 to version 2.0 - Changes from 0.1.67 (jsc#ECO-3319) - Add utils/controlrefcheck.py - Red Hat Enterprise Linux 9 STIG Update Q1 2023 - Include warning for NetworkManager keyfiles in Red Hat Enterprise Linux 9 - OL7 stig v2r10 update - Bump version of OL8 STIG to V1R5 - Various enhancements to SLE profiles spacecmd: - Updated to 4.3.23-1 * Update translation strings
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1204501
- https://bugzilla.suse.com/1208046
- https://bugzilla.suse.com/1208270
- https://bugzilla.suse.com/1213691
- https://bugzilla.suse.com/1213880
- https://www.suse.com/security/cve/CVE-2022-32149
- https://www.suse.com/security/cve/CVE-2022-41723
- https://www.suse.com/security/cve/CVE-2022-46146
- https://www.suse.com/security/cve/CVE-2023-29409
- https://www.suse.com/support/update/announcement/2023/suse-su-20233875-1/