Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:0487-1

Опубликовано: 15 фев. 2024
Источник: suse-cvrf

Описание

Security update for SUSE Manager Client Tools

This update fixes the following issues:

golang-github-lusitaniae-apache_exporter:

  • Do not strip if SUSE Linux Enterprise 15 SP3
  • Exclude debug for Red Hat Enterprise Linux >= 8
  • Build with Go >= 1.20 when the OS is not Red Hat Enterprise Linux

mgr-daemon:

  • Version 4.3.8-1
    • Update translation strings

prometheus-postgres_exporter:

  • Remove duplicated call to systemd requirements
  • Do not build debug if Red Hat Enterprise Linux >= 8
  • Do not strip if SUSE Linux Enterprise 15 SP3
  • Build at least with with Go >= 1.18 on Red Hat Enterprise Linux
  • Build with Go >= 1.20 elsewhere

spacecmd:

  • Version 4.3.26-1
    • Update translation strings

spacewalk-client-tools:

  • Version 4.3.18-1
    • Update translation strings

uyuni-proxy-systemd-services:

  • Version 4.3.10-1
    • Update the image version
  • Version 4.3.9-1
    • Integrate the containerized proxy into the usual rel-eng workflow

Список пакетов

Container suse/manager/5.0/x86_64/server:latest
prometheus-postgres_exporter-0.10.1-150000.1.17.1
Image server-image
prometheus-postgres_exporter-0.10.1-150000.1.17.1
SUSE Manager Client Tools 15
firewalld-prometheus-config-0.1-150000.3.53.1
golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1
golang-github-prometheus-prometheus-2.45.0-150000.3.53.1
grafana-9.5.8-150000.1.60.2
mgr-daemon-4.3.8-150000.1.44.1
prometheus-postgres_exporter-0.10.1-150000.1.17.1
python3-spacewalk-check-4.3.18-150000.3.86.2
python3-spacewalk-client-setup-4.3.18-150000.3.86.2
python3-spacewalk-client-tools-4.3.18-150000.3.86.2
spacecmd-4.3.26-150000.3.113.1
spacewalk-check-4.3.18-150000.3.86.2
spacewalk-client-setup-4.3.18-150000.3.86.2
spacewalk-client-tools-4.3.18-150000.3.86.2
uyuni-proxy-systemd-services-4.3.10-150000.1.15.1
SUSE Manager Client Tools for SLE Micro 5
uyuni-proxy-systemd-services-4.3.10-150000.1.15.1
SUSE Manager Proxy Module 4.3
golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1
SUSE Manager Server Module 4.3
golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1
openSUSE Leap 15.5
golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1
prometheus-postgres_exporter-0.10.1-150000.1.17.1
spacecmd-4.3.26-150000.3.113.1

Описание

All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:prometheus-postgres_exporter-0.10.1-150000.1.17.1
Image server-image:prometheus-postgres_exporter-0.10.1-150000.1.17.1
SUSE Manager Client Tools 15:firewalld-prometheus-config-0.1-150000.3.53.1
SUSE Manager Client Tools 15:golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1

Ссылки

Описание

ansi-regex is vulnerable to Inefficient Regular Expression Complexity


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:prometheus-postgres_exporter-0.10.1-150000.1.17.1
Image server-image:prometheus-postgres_exporter-0.10.1-150000.1.17.1
SUSE Manager Client Tools 15:firewalld-prometheus-config-0.1-150000.3.53.1
SUSE Manager Client Tools 15:golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1

Ссылки

Описание

json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:prometheus-postgres_exporter-0.10.1-150000.1.17.1
Image server-image:prometheus-postgres_exporter-0.10.1-150000.1.17.1
SUSE Manager Client Tools 15:firewalld-prometheus-config-0.1-150000.3.53.1
SUSE Manager Client Tools 15:golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1

Ссылки

Описание

In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:prometheus-postgres_exporter-0.10.1-150000.1.17.1
Image server-image:prometheus-postgres_exporter-0.10.1-150000.1.17.1
SUSE Manager Client Tools 15:firewalld-prometheus-config-0.1-150000.3.53.1
SUSE Manager Client Tools 15:golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1

Ссылки

Описание

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:prometheus-postgres_exporter-0.10.1-150000.1.17.1
Image server-image:prometheus-postgres_exporter-0.10.1-150000.1.17.1
SUSE Manager Client Tools 15:firewalld-prometheus-config-0.1-150000.3.53.1
SUSE Manager Client Tools 15:golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1

Ссылки

Описание

Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and configured. The vulnerability is limited in scope, and only allows access to files with the extension .csv to authenticated users only. Grafana Cloud instances have not been affected by the vulnerability. Versions 8.3.2 and 7.5.12 contain a patch for this issue. There is a workaround available for users who cannot upgrade. Running a reverse proxy in front of Grafana that normalizes the PATH of the request will mitigate the vulnerability. The proxy will have to also be able to handle url encoded paths.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:prometheus-postgres_exporter-0.10.1-150000.1.17.1
Image server-image:prometheus-postgres_exporter-0.10.1-150000.1.17.1
SUSE Manager Client Tools 15:firewalld-prometheus-config-0.1-150000.3.53.1
SUSE Manager Client Tools 15:golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1

Ссылки

Описание

follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:prometheus-postgres_exporter-0.10.1-150000.1.17.1
Image server-image:prometheus-postgres_exporter-0.10.1-150000.1.17.1
SUSE Manager Client Tools 15:firewalld-prometheus-config-0.1-150000.3.53.1
SUSE Manager Client Tools 15:golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1

Ссылки

Описание

Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory. After fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:prometheus-postgres_exporter-0.10.1-150000.1.17.1
Image server-image:prometheus-postgres_exporter-0.10.1-150000.1.17.1
SUSE Manager Client Tools 15:firewalld-prometheus-config-0.1-150000.3.53.1
SUSE Manager Client Tools 15:golang-github-lusitaniae-apache_exporter-1.0.0-150000.1.20.1

Ссылки
Уязвимость SUSE-SU-2024:0487-1