SUSE-EL-9-CLIENT-TOOLS-2024-1525

Source
https://www.suse.com/support/update/announcement/9/suse-el-9-client-tools-2024-1525/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-EL-9-CLIENT-TOOLS-2024-1525.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-EL-9-CLIENT-TOOLS-2024-1525
Upstream
CVE (2)
  • CVE-2024-22231
  • CVE-2024-22232
Related
Published
2024-05-06T09:50:25Z
Modified
2026-07-24T18:24:19Z
Summary
Security update for SUSE Manager Salt Bundle
Details

This update fixes the following issues:

venv-salt-minion:

  • CVE-2024-22231: Prevent directory traversal when creating syndic cache directory on the master (bsc#1219430)
  • CVE-2024-22232: Prevent directory traversal attacks in the master's serve_file method (bsc#1219431)
  • Convert oscap output to UTF-8
  • Make Salt compatible with Python 3.11
  • Ignore non-ascii chars in oscap output (bsc#1219001)
  • Fix detected issues in Salt tests when running on VMs
  • Make importing seco.range thread safe (bsc#1211649)
  • Fix problematic tests and allow smooth tests executions on containers
  • Discover Ansible playbook files as '.yml' or '.yaml' files (bsc#1211888)
  • Prevent exceptions with fileserver.update when called via state (bsc#1218482)
  • Improve pip target override condition with VENV_PIP_TARGET environment variable (bsc#1216850)
  • Fixed KeyError in logs when running a state that fails
References

Affected packages

SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS / venv-salt-minion

Package

Name
venv-salt-minion
Purl
pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3006.0-1.36.3

Ecosystem specific

{
    "binaries":  [
        {
            "venv-salt-minion":  "3006.0-1.36.3"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-EL-9-CLIENT-TOOLS-2024-1525.json"