Revision Date: | 2022-02-18 | Version: | 1 |
Title: | (Important) |
Description: |
This update for cobbler fixes the following issues:
- CVE-2021-45083: Fixed unsafe permissions on sensitive files (bsc#1193671). - CVE-2021-45082: Fixed incomplete template sanitation (bsc#1193678).
The following non-security bugs were fixed:
- Fix issues with installation module logging and validation (bsc#1195918) - Move configuration files ownership to apache (bsc#1195906) - Remove hardcoded test credentials (bsc#1193673) - Prevent log pollution (bsc#1193675) - Missing sanity check on MongoDB configuration file (bsc#1193676)
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1193671 1193673 1193675 1193676 1193678 1195906 1195918 CVE-2014-3710 CVE-2014-8116 CVE-2014-8117 CVE-2017-1000249 CVE-2018-10360 CVE-2019-18218 CVE-2019-8905 CVE-2019-8906 CVE-2019-8907 CVE-2021-45082 CVE-2021-45083
|
Platform(s): | Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM SUSE Linux Enterprise Desktop 15 SP2 SUSE Linux Enterprise High Performance Computing 15 SP2 SUSE Linux Enterprise Module for Basesystem 15 SP2 SUSE Linux Enterprise Server 15 SP2 SUSE Linux Enterprise Server for SAP Applications 15 SP2 SUSE Linux Enterprise Storage 7 SUSE Manager Proxy 4.1 SUSE Manager Server 4.1
| Product(s): | |
Definition Synopsis |
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM is installed AND cobbler-3.1.2-150300.5.14.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
AND Package Information
file-5.32-7.8.1 is installed
OR file-devel-5.32-7.8.1 is installed
OR file-magic-5.32-7.8.1 is installed
OR libmagic1-5.32-7.8.1 is installed
OR libmagic1-32bit-5.32-7.8.1 is installed
|