SUSE-SU-2023:3122-1

Source
https://www.suse.com/support/update/announcement/2023/suse-su-20233122-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3122-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2023:3122-1
Related
Published
2023-08-02T07:11:22Z
Modified
2023-08-02T07:11:22Z
Summary
Security update for SUSE Manager Client Tools
Details

This update fixes the following issues:

python-tornado:

  • Security fixes:
    • CVE-2023-28370: Fixed an open redirect issue in the static file handler (bsc#1211741)

kiwi-desc-saltboot:

  • Update to version 0.1.1687520761.cefb248
    • Add osimage cert package to bootstrap for SUSE Linux Enterprise 12 images (bsc#1204089)

prometheus-blackbox_exporter:

  • Use obscpio for go modules service
  • Set version number
  • Set build date from SOURCEDATEEPOCH
  • Update to 0.24.0 (bsc#1212279, jsc#PED-4556)
    • Requires go1.19
  • Avoid empty validation script
  • Add rc symlink for backwards compatibility

spacecmd:

  • Version 4.3.22-1
    • Bypass traditional systems check on older SUMA instances (bsc#1208612)
References

Affected packages

SUSE:Manager Client Tools 12 / kiwi-desc-saltboot

Package

Name
kiwi-desc-saltboot
Purl
pkg:rpm/suse/kiwi-desc-saltboot&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.1687520761.cefb248-1.35.2

Ecosystem specific

{
    "binaries": [
        {
            "kiwi-desc-saltboot": "0.1.1687520761.cefb248-1.35.2",
            "prometheus-blackbox_exporter": "0.24.0-1.20.3",
            "python3-tornado": "4.2.1-17.7.1",
            "python-tornado": "4.2.1-17.7.1",
            "spacecmd": "4.3.22-38.124.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / prometheus-blackbox_exporter

Package

Name
prometheus-blackbox_exporter
Purl
pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.24.0-1.20.3

Ecosystem specific

{
    "binaries": [
        {
            "kiwi-desc-saltboot": "0.1.1687520761.cefb248-1.35.2",
            "prometheus-blackbox_exporter": "0.24.0-1.20.3",
            "python3-tornado": "4.2.1-17.7.1",
            "python-tornado": "4.2.1-17.7.1",
            "spacecmd": "4.3.22-38.124.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / python-tornado

Package

Name
python-tornado
Purl
pkg:rpm/suse/python-tornado&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.1-17.7.1

Ecosystem specific

{
    "binaries": [
        {
            "kiwi-desc-saltboot": "0.1.1687520761.cefb248-1.35.2",
            "prometheus-blackbox_exporter": "0.24.0-1.20.3",
            "python3-tornado": "4.2.1-17.7.1",
            "python-tornado": "4.2.1-17.7.1",
            "spacecmd": "4.3.22-38.124.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / spacecmd

Package

Name
spacecmd
Purl
pkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.22-38.124.3

Ecosystem specific

{
    "binaries": [
        {
            "kiwi-desc-saltboot": "0.1.1687520761.cefb248-1.35.2",
            "prometheus-blackbox_exporter": "0.24.0-1.20.3",
            "python3-tornado": "4.2.1-17.7.1",
            "python-tornado": "4.2.1-17.7.1",
            "spacecmd": "4.3.22-38.124.3"
        }
    ]
}

SUSE:Linux Enterprise Module for Advanced Systems Management 12 / python-tornado

Package

Name
python-tornado
Purl
pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Advanced%20Systems%20Management%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.1-17.7.1

Ecosystem specific

{
    "binaries": [
        {
            "python3-tornado": "4.2.1-17.7.1",
            "python-tornado": "4.2.1-17.7.1"
        }
    ]
}