SUSE-SU-2020:2648-1

Source
https://www.suse.com/support/update/announcement/2020/suse-su-20202648-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2648-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2020:2648-1
Upstream
  • CVE-2020-8028
Related
  • CVE-2020-8028
Published
2020-09-16T12:23:03Z
Modified
2025-05-02T04:10:23.001858Z
Summary
Security update for SUSE Manager 3.2
Details

This update for SUSE Manager 3.2 fixes the following issues:

salt-netapi-client:

  • Refresh authentication module list to newer Salt versions

spacewalk-admin:

  • Use the Salt API in authenticated and encrypted form (bsc#1175884, CVE-2020-8028)

spacewalk-java:

  • Use the Salt API in authenticated and encrypted form (bsc#1175884, CVE-2020-8028)

spacewalk-setup:

  • Use the Salt API in authenticated and encrypted form (bsc#1175884, CVE-2020-8028)
References

Affected packages

SUSE:Manager Server 3.2 / salt-netapi-client

Package

Name
salt-netapi-client
Purl
pkg:rpm/suse/salt-netapi-client&distro=SUSE%20Manager%20Server%203.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.16.0-4.14.1

Ecosystem specific

{
    "binaries": [
        {
            "salt-netapi-client": "0.16.0-4.14.1",
            "spacewalk-java-postgresql": "2.8.78.30-3.53.1",
            "spacewalk-admin": "2.8.4.7-3.15.1",
            "spacewalk-taskomatic": "2.8.78.30-3.53.1",
            "spacewalk-java-config": "2.8.78.30-3.53.1",
            "spacewalk-java-lib": "2.8.78.30-3.53.1",
            "spacewalk-setup": "2.8.7.11-3.28.1",
            "spacewalk-java": "2.8.78.30-3.53.1",
            "spacewalk-java-oracle": "2.8.78.30-3.53.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2648-1.json"

SUSE:Manager Server 3.2 / spacewalk-admin

Package

Name
spacewalk-admin
Purl
pkg:rpm/suse/spacewalk-admin&distro=SUSE%20Manager%20Server%203.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.4.7-3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "salt-netapi-client": "0.16.0-4.14.1",
            "spacewalk-java-postgresql": "2.8.78.30-3.53.1",
            "spacewalk-admin": "2.8.4.7-3.15.1",
            "spacewalk-taskomatic": "2.8.78.30-3.53.1",
            "spacewalk-java-config": "2.8.78.30-3.53.1",
            "spacewalk-java-lib": "2.8.78.30-3.53.1",
            "spacewalk-setup": "2.8.7.11-3.28.1",
            "spacewalk-java": "2.8.78.30-3.53.1",
            "spacewalk-java-oracle": "2.8.78.30-3.53.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2648-1.json"

SUSE:Manager Server 3.2 / spacewalk-java

Package

Name
spacewalk-java
Purl
pkg:rpm/suse/spacewalk-java&distro=SUSE%20Manager%20Server%203.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.78.30-3.53.1

Ecosystem specific

{
    "binaries": [
        {
            "salt-netapi-client": "0.16.0-4.14.1",
            "spacewalk-java-postgresql": "2.8.78.30-3.53.1",
            "spacewalk-admin": "2.8.4.7-3.15.1",
            "spacewalk-taskomatic": "2.8.78.30-3.53.1",
            "spacewalk-java-config": "2.8.78.30-3.53.1",
            "spacewalk-java-lib": "2.8.78.30-3.53.1",
            "spacewalk-setup": "2.8.7.11-3.28.1",
            "spacewalk-java": "2.8.78.30-3.53.1",
            "spacewalk-java-oracle": "2.8.78.30-3.53.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2648-1.json"

SUSE:Manager Server 3.2 / spacewalk-setup

Package

Name
spacewalk-setup
Purl
pkg:rpm/suse/spacewalk-setup&distro=SUSE%20Manager%20Server%203.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.7.11-3.28.1

Ecosystem specific

{
    "binaries": [
        {
            "salt-netapi-client": "0.16.0-4.14.1",
            "spacewalk-java-postgresql": "2.8.78.30-3.53.1",
            "spacewalk-admin": "2.8.4.7-3.15.1",
            "spacewalk-taskomatic": "2.8.78.30-3.53.1",
            "spacewalk-java-config": "2.8.78.30-3.53.1",
            "spacewalk-java-lib": "2.8.78.30-3.53.1",
            "spacewalk-setup": "2.8.7.11-3.28.1",
            "spacewalk-java": "2.8.78.30-3.53.1",
            "spacewalk-java-oracle": "2.8.78.30-3.53.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2648-1.json"