FlawAtlas
Search the atlas
SUSE-SU-2023:3875-1 Not scored

Security update for SUSE Manager Client Tools

This update fixes the following issues: golang-github-lusitaniae-apache_exporter: - Security issues fixed: * CVE-2022-32149: Fix denial of service vulnerability (bsc#1204501) * CVE-2022-41723: Fix uncontrolled resource consumption (bsc#1208270) * CVE-2022-46146: Fix authentication bypass vulnarability (bsc#1208046) - Changes and bugs fixed: * Updated to 1.0.0 (jsc#PED-5405) + Improved flag parsing + Added support for custom headers * Changes from 0.13.1 + Fix panic caused by missing flagConfig options * Changes from 0.11.0 (jsc#SLE-24791) + Add TLS support + Switch to logger, please check --log.level and --log.format flags * Changes from 0.10.1 + Bugfix: Reset ProxyBalancer metrics on each scrape to remove stale data * Changes from 0.10.0 + Add Apache Proxy and other metrics * Changes from 0.8.0 + Change commandline flags + Add metrics: Apache version, request duration total * Changes from 0.7.0 + Handle OS TERM signals * Changes from 0.6.0 + Add option to override host name * Added support for Red Hat Enterprise Linux * Added AppArmor profile * Added sandboxing options to systemd service unit * Build using promu * Build with Go 1.19 * Exclude s390 architecture golang-github-prometheus-node_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. golang-github-QubitProducts-exporter_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. prometheus-postgres_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. scap-security-guide: - Updated to 0.1.69 (jsc#ECO-3319) - Introduce a JSON build manifest - Introduce a script to compare ComplianceAsCode versions - Introduce CCN profiles for Red Hat Enterprise Linux 9 - Map rules to components - products/anolis23: supports Anolis OS 23 - Render components to HTML - Store rendered control files - Test and use rules to components mapping - Use distributed product properties - Revert patch that breaks the SLE hardening (bsc#1213691) - Changes from 0.1.68 (jsc#ECO-3319) - Bump OL8 STIG version to V1R6 - Introduce a Product class, make the project work with it - Introduce Fedora and Firefox CaC profiles for common workstation users - OL7 DISA STIG v2r11 update - Publish rendered policy artifacts - Update ANSSI BP-028 to version 2.0 - Changes from 0.1.67 (jsc#ECO-3319) - Add utils/controlrefcheck.py - Red Hat Enterprise Linux 9 STIG Update Q1 2023 - Include warning for NetworkManager keyfiles in Red Hat Enterprise Linux 9 - OL7 stig v2r10 update - Bump version of OL8 STIG to V1R5 - Various enhancements to SLE profiles spacecmd: - Updated to 4.3.23-1 * Update translation strings

Exploit probability Not scored
Published September 28, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:EL-9:Update:Products:ManagerTools:Update spacecmd
SUSE:EL-9:Update:Products:ManagerTools:Update golang-github-QubitProducts-exporter_exporter
SUSE:EL-9:Update:Products:ManagerTools:Update golang-github-lusitaniae-apache_exporter
SUSE:EL-9:Update:Products:ManagerTools:Update golang-github-prometheus-node_exporter
SUSE:EL-9:Update:Products:ManagerTools:Update prometheus-postgres_exporter
SUSE:EL-9:Update:Products:ManagerTools:Update scap-security-guide
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS golang-github-QubitProducts-exporter_exporter
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS golang-github-lusitaniae-apache_exporter
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS golang-github-prometheus-node_exporter
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS prometheus-postgres_exporter
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS scap-security-guide
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS spacecmd

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:3875-1

This update fixes the following issues: golang-github-lusitaniae-apache_exporter: - Security issues fixed: * CVE-2022-32149: Fix denial of service vulnerability (bsc#1204501) * CVE-2022-41723: Fix uncontrolled resource consumption (bsc#1208270) * CVE-2022-46146: Fix authentication bypass vulnarability (bsc#1208046) - Changes and bugs fixed: * Updated to 1.0.0 (jsc#PED-5405) + Improved flag parsing + Added support for custom headers * Changes from 0.13.1 + Fix panic caused by missing flagConfig options * Changes from 0.11.0 (jsc#SLE-24791) + Add TLS support + Switch to logger, please check --log.level and --log.format flags * Changes from 0.10.1 + Bugfix: Reset ProxyBalancer metrics on each scrape to remove stale data * Changes from 0.10.0 + Add Apache Proxy and other metrics * Changes from 0.8.0 + Change commandline flags + Add metrics: Apache version, request duration total * Changes from 0.7.0 + Handle OS TERM signals * Changes from 0.6.0 + Add option to override host name * Added support for Red Hat Enterprise Linux * Added AppArmor profile * Added sandboxing options to systemd service unit * Build using promu * Build with Go 1.19 * Exclude s390 architecture golang-github-prometheus-node_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. golang-github-QubitProducts-exporter_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. prometheus-postgres_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. scap-security-guide: - Updated to 0.1.69 (jsc#ECO-3319) - Introduce a JSON build manifest - Introduce a script to compare ComplianceAsCode versions - Introduce CCN profiles for Red Hat Enterprise Linux 9 - Map rules to components - products/anolis23: supports Anolis OS 23 - Render components to HTML - Store rendered control files - Test and use rules to components mapping - Use distributed product properties - Revert patch that breaks the SLE hardening (bsc#1213691) - Changes from 0.1.68 (jsc#ECO-3319) - Bump OL8 STIG version to V1R6 - Introduce a Product class, make the project work with it - Introduce Fedora and Firefox CaC profiles for common workstation users - OL7 DISA STIG v2r11 update - Publish rendered policy artifacts - Update ANSSI BP-028 to version 2.0 - Changes from 0.1.67 (jsc#ECO-3319) - Add utils/controlrefcheck.py - Red Hat Enterprise Linux 9 STIG Update Q1 2023 - Include warning for NetworkManager keyfiles in Red Hat Enterprise Linux 9 - OL7 stig v2r10 update - Bump version of OL8 STIG to V1R5 - Various enhancements to SLE profiles spacecmd: - Updated to 4.3.23-1 * Update translation strings

View original source

05 / REFERENCES

Further evidence