[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2018:3815-1 -- SLES salt, python2-salt, python3-salt

ID: oval:org.secpod.oval:def:89049635Date: (C)2023-12-20   (M)2023-12-26
Class: PATCHFamily: unix




This update for salt fixes the following issues: Security issues fixed: - CVE-2018-15750: Fixed directory traversal vulnerability in salt-api . - CVE-2018-15751: Fixed remote authentication bypass in salt-api that allows to execute arbitrary commands . Non-security issues fixed: - Improved handling of LDAP group id. gid is no longer treated as a string, which could have lead to faulty group creations . - Fixed async call to process manager . - Fixed OS arch detection when RPM is not installed .

Platform:
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
Product:
salt
python2-salt
python3-salt
Reference:
SUSE-SU-2018:3815-1
CVE-2018-15750
CVE-2018-15751
CVE    2
CVE-2018-15750
CVE-2018-15751
CPE    37
cpe:/a:python:python2-salt
cpe:/a:saltstack:salt:0.6.0
cpe:/o:suse:suse_linux_enterprise_server:15
cpe:/a:python:python3-salt
...

© SecPod Technologies