Oval Definition:oval:org.opensuse.security:def:100753
Revision Date:2022-02-18Version:1
Title: (Important)
Description:

This update for cobbler fixes the following issues:

- CVE-2021-45083: Fixed unsafe permissions on sensitive files (bsc#1193671). - CVE-2021-45082: Fixed incomplete template sanitation (bsc#1193678).

The following non-security bugs were fixed:

- Fix issues with installation module logging and validation (bsc#1195918) - Move configuration files ownership to apache (bsc#1195906) - Remove hardcoded test credentials (bsc#1193673) - Prevent log pollution (bsc#1193675) - Missing sanity check on MongoDB configuration file (bsc#1193676)
Family:unixClass:patch
Status:Reference(s):1193671
1193673
1193675
1193676
1193678
1195906
1195918
CVE-2013-2002
CVE-2013-2005
CVE-2021-45082
CVE-2021-45083
Platform(s):Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Storage 7
SUSE Manager Proxy 4.1
SUSE Manager Server 4.1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • AND libXt6-32bit-1.1.5-2.24 is installed
  • Definition Synopsis
  • Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE is installed
  • AND cobbler-3.1.2-150300.5.14.1 is installed
  • BACK