[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2023:4386-1 -- SLES salt, python3-salt

ID: oval:org.secpod.oval:def:89051084Date: (C)2024-01-23   (M)2024-01-23
Class: PATCHFamily: unix




This update for salt fixes the following issues: Security issues fixed: * CVE-2023-34049: arbitrary code execution via symlink attack Bugs fixed: * Fix optimization_order opt to prevent testsuite fails * Improve salt.utils.json.find_json to avoid fails * Use salt-call from salt bundle with transactional_update * Only call native_str on curl_debug message in tornado when needed * Implement the calling for batch async from the salt CLI * Fix calculation of SLS context vars when trailing dots on targetted sls/state * Rename salt-tests to python3-salt-testsuite * Allow all primitive grain types for autosign_grains ## Special Instructions and Notes:

Platform:
SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise Server 15 SP5
Product:
salt
python3-salt
Reference:
SUSE-SU-2023:4386-1
CVE-2023-34049
CVE    1
CVE-2023-34049
CPE    2
cpe:/a:saltstack:salt
cpe:/a:python:python3-salt

© SecPod Technologies