Security update 5.1.4 for Multi-Linux Manager Client Tools
This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248707) golang-github-boynux-squid_exporter: - Non customer facing changes golang-github-lusitaniae-apache_exporter: - Non customer facing changes golang-github-prometheus-node_exporter: - Update to 1.10.2: * [BUGFIX] meminfo: Fix typo in Zswap metric name - Update to 1.10.1: * [BUGFIX] filesystem: Fix mount points being collected multiple times * [BUGFIX] filesystem: Refactor mountinfo parsing (bsc#1261810) * [BUGFIX] meminfo: Add Zswap/Zswapped metrics - Update to 1.10.0: * [CHANGE] mdadm: Use sysfs for RAID metrics * [CHANGE] filesystem: Add erofs in default excluded fs * [CHANGE] tcpstat: Use std lib binary.NativeEndian * [FEATURE] pcidevice: Add new collector for PCIe devices * [FEATURE] systemd: Add Virtualization metrics * [FEATURE] swaps: Add new collector * [ENHANCEMENT] wifi: Add packet received and transmitted metrics * [ENHANCEMENT] filesystem: Take super options into account for read-only * [ENHANCEMENT] pcidevice: Add additional metrics * [ENHANCEMENT] perf: Add tlb_data metrics * [BUGFIX] diskstats: Simplify condition * [BUGFIX] thermal: Sanitize darwin thermal strings * [BUGFIX] cpufreq: Fix: collector enable * [BUGFIX] ethtool: Fix returning 0 for sanitized metrics * [BUGFIX] systemd: Fix logging race mgr-push: - Version 5.2.4-0 * Non customer facing changes - Version 5.2.3-0 * Non customer facing changes - Version 5.2.2-0 * Non customer facing changes - Version 5.2.1-0 * Non customer facing changes prometheus-postgres_exporter: - CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) rhnlib: - Version 5.2.5-0 * Non customer facing changes - Version 5.2.4-0 * Non customer facing changes - Version 5.2.3-0 * Non customer facing changes - Version 5.2.2-0 * Non customer facing changes - Version 5.2.1-0 * Non customer facing changes spacecmd: - Version 5.2.8-0 * Non customer facing changes - Version 5.2.7-0 * Add proxy_container_config_nossl command - Version 5.2.6-0 * Update translation strings - Version 5.2.5-0 * Update translation strings - Version 5.2.4-0 * Update translation strings - Version 5.2.3-0 * Fix typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches - Version 5.2.2-0 * Update translation strings - Version 5.2.1-0 * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fix methods in api namespace in spacecmd (bsc#1249532) spacewalk-client-tools: - Version 5.2.6-0 * Non customer facing changes - Version 5.2.5-0 * Update translations - Version 5.2.4-0 * Non customer facing changes - Version 5.2.3-0 * Non customer facing changes - Version 5.2.2-0 * Update translation strings1260806 - Version 5.2.1-0 * Non customer facing changes supportutils-plugin-susemanager-client: - Version 5.2.3-0 * Non customer facing changes - Version 5.2.2-0 * Non customer facing changes - Version 5.2.1-0 * Non customer facing changes uyuni-tools: - Version 5.2.12-0 * No customer facing changes - Version 5.2.11-0 * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) - Version 5.2.10-0 * Preserve hub replicas during upgrade (bsc#1262708) * Add mgrctl commands 'ssh' and 'ssh remove_known_host' * Use a startup check with no limit for the main server container bsc#1263157) * Make uyuni-server service dependent on uyuni-db (bsc#1263823) * Internal SANs for db and reportdb are no longer required * Generate the same certificate for server and reportdb * Update the default tag to 5.1.3.1 (bsc#1262760) * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Use correct CA for Report DB (bsc#1260806) - Version 5.2.9-0 * Do not stop container on health check failure Temporary workaround for bsc#1263157 - Version 5.2.8-0 * Generate service template only after secrets are created - Version 5.2.7-0 * Do not require admin secrets on upgrades (bsc#1262409) - Version 5.2.6-0 * Use podman secrets for SSL on proxy * Fix db online backup with new pg_hba settings * mgrctl copy can now infer target name if not set * No need to expose the cobbler port * Add the TFTP port back to the proxy (bsc#1260905) * Fix the macros in the spec file (bsc#1229105) * Disable TFTP by default on the server * Bump zerolog to 1.34 * Ignore spacewalk-service stop return code. * Stop automatically unhealthy container * Use container based server setup instead tools bundled one - Version 5.2.5-0 * Remove migrate command * Remove template script from mgradm: use the one in the image * Split the TFTP server into a separate container * Adjust mgrctl server filter to work with the new helm chart labels * Remove hub register command * Remove the Kubernetes install and upgrade from mgrpxy - Version 5.2.4-0 * Move the SSL checks at the begining of the migration * Remove Kubernetes code for the mgrdam * Use single universal image to migrate between PostgreSQL versions - Version 5.2.3-0 * Update translation strings - Version 5.2.2-0 * Non customer facing changes - Version 5.2.1-0 * Actually use the --dbupgrade-tag parameter when computing the image URL (bsc#1249400) * Detect custom Apache and Squid config in the /etc/uyuni/proxy folder * Fix generated DB certificate subject alternate names * add --registry-host, --registry-user and --registry-password to pull images from an authenticate registry * deprecate --registry uyuni-common-libs: - Version 5.2.5-0 * Remove legacy md5/sha1 fallback imports from checksum module; use hashlib directly - Version 5.2.4-0 * Build uyuni-common-libs noarch - Version 5.2.3-0 * Non customer facing changes - Version 5.2.2-0 * Non customer facing changes - Version 5.2.1-0 * Bump version to 5.2.0
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248707) golang-github-boynux-squid_exporter: - Non customer facing changes golang-github-lusitaniae-apache_exporter: - Non customer facing changes golang-github-prometheus-node_exporter: - Update to 1.10.2: * [BUGFIX] meminfo: Fix typo in Zswap metric name - Update to 1.10.1: * [BUGFIX] filesystem: Fix mount points being collected multiple times * [BUGFIX] filesystem: Refactor mountinfo parsing (bsc#1261810) * [BUGFIX] meminfo: Add Zswap/Zswapped metrics - Update to 1.10.0: * [CHANGE] mdadm: Use sysfs for RAID metrics * [CHANGE] filesystem: Add erofs in default excluded fs * [CHANGE] tcpstat: Use std lib binary.NativeEndian * [FEATURE] pcidevice: Add new collector for PCIe devices * [FEATURE] systemd: Add Virtualization metrics * [FEATURE] swaps: Add new collector * [ENHANCEMENT] wifi: Add packet received and transmitted metrics * [ENHANCEMENT] filesystem: Take super options into account for read-only * [ENHANCEMENT] pcidevice: Add additional metrics * [ENHANCEMENT] perf: Add tlb_data metrics * [BUGFIX] diskstats: Simplify condition * [BUGFIX] thermal: Sanitize darwin thermal strings * [BUGFIX] cpufreq: Fix: collector enable * [BUGFIX] ethtool: Fix returning 0 for sanitized metrics * [BUGFIX] systemd: Fix logging race mgr-push: - Version 5.2.4-0 * Non customer facing changes - Version 5.2.3-0 * Non customer facing changes - Version 5.2.2-0 * Non customer facing changes - Version 5.2.1-0 * Non customer facing changes prometheus-postgres_exporter: - CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) rhnlib: - Version 5.2.5-0 * Non customer facing changes - Version 5.2.4-0 * Non customer facing changes - Version 5.2.3-0 * Non customer facing changes - Version 5.2.2-0 * Non customer facing changes - Version 5.2.1-0 * Non customer facing changes spacecmd: - Version 5.2.8-0 * Non customer facing changes - Version 5.2.7-0 * Add proxy_container_config_nossl command - Version 5.2.6-0 * Update translation strings - Version 5.2.5-0 * Update translation strings - Version 5.2.4-0 * Update translation strings - Version 5.2.3-0 * Fix typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches - Version 5.2.2-0 * Update translation strings - Version 5.2.1-0 * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fix methods in api namespace in spacecmd (bsc#1249532) spacewalk-client-tools: - Version 5.2.6-0 * Non customer facing changes - Version 5.2.5-0 * Update translations - Version 5.2.4-0 * Non customer facing changes - Version 5.2.3-0 * Non customer facing changes - Version 5.2.2-0 * Update translation strings1260806 - Version 5.2.1-0 * Non customer facing changes supportutils-plugin-susemanager-client: - Version 5.2.3-0 * Non customer facing changes - Version 5.2.2-0 * Non customer facing changes - Version 5.2.1-0 * Non customer facing changes uyuni-tools: - Version 5.2.12-0 * No customer facing changes - Version 5.2.11-0 * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) - Version 5.2.10-0 * Preserve hub replicas during upgrade (bsc#1262708) * Add mgrctl commands 'ssh' and 'ssh remove_known_host' * Use a startup check with no limit for the main server container bsc#1263157) * Make uyuni-server service dependent on uyuni-db (bsc#1263823) * Internal SANs for db and reportdb are no longer required * Generate the same certificate for server and reportdb * Update the default tag to 5.1.3.1 (bsc#1262760) * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Use correct CA for Report DB (bsc#1260806) - Version 5.2.9-0 * Do not stop container on health check failure Temporary workaround for bsc#1263157 - Version 5.2.8-0 * Generate service template only after secrets are created - Version 5.2.7-0 * Do not require admin secrets on upgrades (bsc#1262409) - Version 5.2.6-0 * Use podman secrets for SSL on proxy * Fix db online backup with new pg_hba settings * mgrctl copy can now infer target name if not set * No need to expose the cobbler port * Add the TFTP port back to the proxy (bsc#1260905) * Fix the macros in the spec file (bsc#1229105) * Disable TFTP by default on the server * Bump zerolog to 1.34 * Ignore spacewalk-service stop return code. * Stop automatically unhealthy container * Use container based server setup instead tools bundled one - Version 5.2.5-0 * Remove migrate command * Remove template script from mgradm: use the one in the image * Split the TFTP server into a separate container * Adjust mgrctl server filter to work with the new helm chart labels * Remove hub register command * Remove the Kubernetes install and upgrade from mgrpxy - Version 5.2.4-0 * Move the SSL checks at the begining of the migration * Remove Kubernetes code for the mgrdam * Use single universal image to migrate between PostgreSQL versions - Version 5.2.3-0 * Update translation strings - Version 5.2.2-0 * Non customer facing changes - Version 5.2.1-0 * Actually use the --dbupgrade-tag parameter when computing the image URL (bsc#1249400) * Detect custom Apache and Squid config in the /etc/uyuni/proxy folder * Fix generated DB certificate subject alternate names * add --registry-host, --registry-user and --registry-password to pull images from an authenticate registry * deprecate --registry uyuni-common-libs: - Version 5.2.5-0 * Remove legacy md5/sha1 fallback imports from checksum module; use hashlib directly - Version 5.2.4-0 * Build uyuni-common-libs noarch - Version 5.2.3-0 * Non customer facing changes - Version 5.2.2-0 * Non customer facing changes - Version 5.2.1-0 * Bump version to 5.2.0
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1227579
- https://bugzilla.suse.com/1229105
- https://bugzilla.suse.com/1232641
- https://bugzilla.suse.com/1248699
- https://bugzilla.suse.com/1248707
- https://bugzilla.suse.com/1249400
- https://bugzilla.suse.com/1249532
- https://bugzilla.suse.com/1253174
- https://bugzilla.suse.com/1259739
- https://bugzilla.suse.com/1260806
- https://bugzilla.suse.com/1260905
- https://bugzilla.suse.com/1261810
- https://bugzilla.suse.com/1261902
- https://bugzilla.suse.com/1262409
- https://bugzilla.suse.com/1262708
- https://bugzilla.suse.com/1262760
- https://bugzilla.suse.com/1263157
- https://bugzilla.suse.com/1263823
- https://bugzilla.suse.com/1266012
- https://www.suse.com/security/cve/CVE-2022-21698
- https://www.suse.com/support/update/announcement/2026/suse-su-20262766-1/