gpp_maybe
Security update for suse manager salt bundle
SUSE-SLE-Module-SUSE-Manager-Server-4.3-2024-1518
This update fixes the following issues: venv-salt-minion: - Security issues fixed: * CVE-2024-22231: Prevent directory traversal when creating syndic cache directory on the master (bsc#1219430) * CVE-2024-22232: Prevent directory traversal attacks in the master's serve_file method (bsc#1219431) - Bugs fixed: * Convert oscap output to UTF-8 * Make Salt compatible with Python 3.11 * Ignore non-ascii chars in oscap output (bsc#1219001) * Fix detected issues in Salt tests when running on VMs * Make importing seco.range thread safe (bsc#1211649) * Fix problematic tests and allow smooth tests executions on containers * Discover Ansible playbook files as "*.yml" or "*.yaml" files (bsc#1211888) * Prevent exceptions with fileserver.update when called via state (bsc#1218482) * Improve pip target override condition with VENV_PIP_TARGET environment variable (bsc#1216850) * Fixed KeyError in logs when running a state that fails
-
Release DateMay 6 2024
-
ReferencesBugzilla: 1211649, 1211888, 1216850, 1218482, 1219001, 1219430, 1219431
CVEs: CVE-2024-22231, CVE-2024-22232 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Manager Server Module 4.3 ppc64le
-
Packages
SUSE Manager Server Module 4.3 s390x
-
Packages
SUSE Manager Server Module 4.3 x86_64
-
Packages