[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2023:4388-1 -- SLES salt, python3-simplejson, python-simplejson-debugsource, python-simplejson-debuginfo, python3-salt

ID: oval:org.secpod.oval:def:89051088Date: (C)2024-01-23   (M)2024-01-23
Class: PATCHFamily: unix




This update for salt fixes the following issues: Security issues fixed: * CVE-2023-34049: arbitrary code execution via symlink attack Bugs fixed: * Fix optimization_order opt to prevent testsuite fails * Improve salt.utils.json.find_json to avoid fails * Use salt-call from salt bundle with transactional_update * Only call native_str on curl_debug message in tornado when needed * Implement the calling for batch async from the salt CLI * Fix calculation of SLS context vars when trailing dots on targetted sls/state * Rename salt-tests to python3-salt-testsuite * Allow all primitive grain types for autosign_grains ## Special Instructions and Notes:

Platform:
SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
Product:
salt
python3-simplejson
python-simplejson-debugsource
python-simplejson-debuginfo
python3-salt
Reference:
SUSE-SU-2023:4388-1
CVE-2023-34049
CVE    1
CVE-2023-34049
CPE    5
cpe:/a:saltstack:salt
cpe:/a:python:python3-salt
cpe:/o:suse:suse_linux_enterprise_server:15:sp4
cpe:/o:suse:suse_linux_enterprise_server:15:sp3
...

© SecPod Technologies