SUSE-SU-2023:3867-1

Source
https://www.suse.com/support/update/announcement/2023/suse-su-20233867-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3867-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2023:3867-1
Related
Published
2023-09-28T11:42:18Z
Modified
2023-09-28T11:42:18Z
Summary
Security update for SUSE Manager Client Tools
Details

This update fixes the following issues:

golang-github-lusitaniae-apache_exporter:

  • Security issues fixed:
    • CVE-2022-32149: Fix denial of service vulnerability (bsc#1204501)
    • CVE-2022-41723: Fix uncontrolled resource consumption (bsc#1208270)
    • CVE-2022-46146: Fix authentication bypass vulnarability (bsc#1208046)
  • Changes and bugs fixed:
    • Updated to 1.0.0 (jsc#PED-5405)
      • Improved flag parsing
      • Added support for custom headers
    • Changes from 0.13.1
      • Fix panic caused by missing flagConfig options
    • Added AppArmor profile
    • Added sandboxing options to systemd service unit
    • Build using promu
    • Build with Go 1.19
    • Exclude s390 architecture

golang-github-prometheus-alertmanager:

  • CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

golang-github-prometheus-node_exporter:

  • CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

golang-github-prometheus-prometheus:

  • This update introduces breaking changes. Please, read carefully the provided informations.
  • Security issues fixed:
    • CVE-2022-41723: Fix uncontrolled resource consumption by updating Go to version 1.20.1 (bsc#1208298)
  • Updated to 2.45.0 (jsc#PED-5406):
    • [FEATURE] API: New limit parameter to limit the number of items returned by /api/v1/status/tsdb endpoint
    • [FEATURE] Config: Add limits to global config
    • [FEATURE] Consul SD: Added support for path_prefix
    • [FEATURE] Native histograms: Add option to scrape both classic and native histograms.
    • [FEATURE] Native histograms: Added support for two more arithmetic operators avg_over_time and sum_over_time
    • [FEATURE] Promtool: When providing the block id, only one block will be loaded and analyzed
    • [FEATURE] Remote-write: New Azure ad configuration to support remote writing directly to Azure Monitor workspace
    • [FEATURE] TSDB: Samples per chunk are now configurable with flag storage.tsdb.samples-per-chunk. By default set to its former value 120
    • [ENHANCEMENT] Native histograms: bucket size can now be limited to avoid scrape fails
    • [ENHANCEMENT] TSDB: Dropped series are now deleted from the WAL sooner
    • [BUGFIX] Native histograms: ChunkSeries iterator now checks if a new sample can be appended to the open chunk
    • [BUGFIX] Native histograms: Fix Histogram Appender Appendable() segfault
    • [BUGFIX] Native histograms: Fix setting reset header to gauge histograms in seriesToChunkEncoder
    • [BUGFIX] TSDB: Tombstone intervals are not modified after Get() call
    • [BUGFIX] TSDB: Use path/filepath to set the WAL directory.
  • Changes from 2.44.0:
    • [FEATURE] Remote-read: Handle native histograms
    • [FEATURE] Promtool: Health and readiness check of prometheus server in CLI
    • [FEATURE] PromQL: Add query_samples_total metric, the total number of samples loaded by all queries
    • [ENHANCEMENT] Storage: Optimise buffer used to iterate through samples
    • [ENHANCEMENT] Scrape: Reduce memory allocations on target labels
    • [ENHANCEMENT] PromQL: Use faster heap method for topk() / bottomk()
    • [ENHANCEMENT] Rules API: Allow filtering by rule name
    • [ENHANCEMENT] Native Histograms: Various fixes and improvements
    • [ENHANCEMENT] UI: Search of scraping pools is now case-insensitive
    • [ENHANCEMENT] TSDB: Add an affirmative log message for successful WAL repair
    • [BUGFIX] TSDB: Block compaction failed when shutting down
    • [BUGFIX] TSDB: Out-of-order chunks could be ignored if the write-behind log was deleted
  • Changes from 2.43.1
    • [BUGFIX] Labels: Set() after Del() would be ignored, which broke some relabeling rules
  • Changes from 2.43.0:
    • [FEATURE] Promtool: Add HTTP client configuration to query commands
    • [FEATURE] Scrape: Add include_scrape_configs to include scrape configs from different files
    • [FEATURE] HTTP client: Add no_proxy to exclude URLs from proxied requests
    • [FEATURE] HTTP client: Add proxy_from_enviroment to read proxies from env variables
    • [ENHANCEMENT] API: Add support for setting lookback delta per query via the API
    • [ENHANCEMENT] API: Change HTTP status code from 503/422 to 499 if a request is canceled
    • [ENHANCEMENT] Scrape: Allow exemplars for all metric types
    • [ENHANCEMENT] TSDB: Add metrics for head chunks and WAL folders size
    • [ENHANCEMENT] TSDB: Automatically remove incorrect snapshot with index that is ahead of WAL
    • [ENHANCEMENT] TSDB: Improve Prometheus parser error outputs to be more comprehensible
    • [ENHANCEMENT] UI: Scope group by labels to metric in autocompletion
    • [BUGFIX] Scrape: Fix prometheus_target_scrape_pool_target_limit metric not set before reloading
    • [BUGFIX] TSDB: Correctly update prometheus_tsdb_head_chunks_removed_total and prometheus_tsdb_head_chunks metrics when reading WAL
    • [BUGFIX] TSDB: Use the correct unit (seconds) when recording out-of-order append deltas in the prometheus_tsdb_sample_ooo_delta metric
  • Changes from 2.42.0: This release comes with a new feature coverage for native histograms and breaking changes. If you are trying native histograms already, we recommend you remove the wal directory when upgrading. Because the old WAL record for native histograms is not backward compatible in v2.42.0, this will lead to some data loss for the latest data. Additionally, if you scrape 'float histograms' or use recording rules on native histograms in v2.42.0 (which writes float histograms), it is a one-way street since older versions do not support float histograms.
    • [CHANGE] breaking TSDB: Changed WAL record format for the experimental native histograms
    • [FEATURE] Add 'keepfiringfor' field to alerting rules
    • [FEATURE] Promtool: Add support of selecting timeseries for TSDB dump
    • [ENHANCEMENT] Agent: Native histogram support.
    • [ENHANCEMENT] Rules: Support native histograms in recording rules
    • [ENHANCEMENT] SD: Add container ID as a meta label for pod targets for Kubernetes
    • [ENHANCEMENT] SD: Add VM size label to azure service discovery
    • [ENHANCEMENT] Support native histograms in federation
    • [ENHANCEMENT] TSDB: Add gauge histogram support
    • [ENHANCEMENT] TSDB/Scrape: Support FloatHistogram that represents buckets as float64 values
    • [ENHANCEMENT] UI: Show individual scrape pools on /targets page
  • Changes from 2.41.0:
    • [FEATURE] Relabeling: Add keepequal and dropequal relabel actions
    • [FEATURE] Add support for HTTP proxy headers
    • [ENHANCEMENT] Reload private certificates when changed on disk
    • [ENHANCEMENT] Add maxversion to specify maximum TLS version in tlsconfig
    • [ENHANCEMENT] Add goos and goarch labels to prometheusbuildinfo
    • [ENHANCEMENT] SD: Add proxy support for EC2 and LightSail SDs
    • [ENHANCEMENT] SD: Add new metric prometheussdfilewatchererrors_total
    • [ENHANCEMENT] Remote Read: Use a pool to speed up marshalling
    • [ENHANCEMENT] TSDB: Improve handling of tombstoned chunks in iterators
    • [ENHANCEMENT] TSDB: Optimize postings offset table reading
    • [BUGFIX] Scrape: Validate the metric name, label names, and label values after relabeling
    • [BUGFIX] Remote Write receiver and rule manager: Fix error handling
  • Changes from 2.40.7:
    • [BUGFIX] TSDB: Fix queries involving negative buckets of native histograms
  • Changes from 2.40.5:
    • [BUGFIX] TSDB: Fix queries involving native histograms due to improper reset of iterators
  • Changes from 2.40.3:
    • [BUGFIX] TSDB: Fix compaction after a deletion is called
  • Changes from 2.40.2:
    • [BUGFIX] UI: Fix black-on-black metric name color in dark mode
  • Changes from 2.40.1:
    • [BUGFIX] TSDB: Fix alignment for atomic int64 for 32 bit architecture
    • [BUGFIX] Scrape: Fix accept headers
  • Changes from 2.40.0:
    • [FEATURE] Add experimental support for native histograms. Enable with the flag --enable-feature=native-histograms.
    • [FEATURE] SD: Add service discovery for OVHcloud
    • [ENHANCEMENT] Kubernetes SD: Use protobuf encoding
    • [ENHANCEMENT] TSDB: Use golang.org/x/exp/slices for improved sorting speed
    • [ENHANCEMENT] Consul SD: Add enterprise admin partitions. Adds metaconsulpartition label. Adds partition config in consulsdconfig
    • [BUGFIX] API: Fix API error codes for /api/v1/labels and /api/v1/series
  • Changes from 2.39.1:
    • [BUGFIX] Rules: Fix notifier relabel changing the labels on active alerts
  • Changes from 2.39.0:
    • [FEATURE] experimental TSDB: Add support for ingesting out-of-order samples. This is configured via outofordertimewindow field in the config file; check config file docs for more info
    • [ENHANCEMENT] API: /-/healthy and /-/ready API calls now also respond to a HEAD request on top of existing GET support.
    • [ENHANCEMENT] PuppetDB SD: Add metapuppetdbquery label.
    • [ENHANCEMENT] AWS EC2 SD: Add metaec2region label.
    • [ENHANCEMENT] AWS Lightsail SD: Add metalightsailregion label.
    • [ENHANCEMENT] Scrape: Optimise relabeling by re-using memory.
    • [ENHANCEMENT] TSDB: Improve WAL replay timings.
    • [ENHANCEMENT] TSDB: Optimise memory by not storing unnecessary data in the memory.
    • [ENHANCEMENT] TSDB: Allow overlapping blocks by default. --storage.tsdb.allow-overlapping-blocks now has no effect.
    • [ENHANCEMENT] UI: Click to copy label-value pair from query result to clipboard.
    • [BUGFIX] TSDB: Turn off isolation for Head compaction to fix a memory leak.
    • [BUGFIX] TSDB: Fix 'invalid magic number 0' error on Prometheus startup.
    • [BUGFIX] PromQL: Properly close file descriptor when logging unfinished queries.
    • [BUGFIX] Agent: Fix validation of flag options and prevent WAL from growing more than desired.
  • Changes from 2.38.0:
    • [FEATURE]: Web: Add a /api/v1/formatquery HTTP API endpoint that allows pretty-formatting PromQL expressions.
    • [FEATURE]: UI: Add support for formatting PromQL expressions in the UI.
    • [FEATURE]: DNS SD: Support MX records for discovering targets.
    • [FEATURE]: Templates: Add toTime() template function that allows converting sample timestamps to Go time.Time values
    • [ENHANCEMENT]: Kubernetes SD: Add metakubernetesserviceportnumber meta label indicating the service port number. _metakubernetespodcontainerimage meta label indicating the container image.
    • [ENHANCEMENT]: PromQL: When a query panics, also log the query itself alongside the panic message.
    • [ENHANCEMENT]: UI: Tweak colors in the dark theme to improve the contrast ratio.
    • [ENHANCEMENT]: Web: Speed up calls to /api/v1/rules by avoiding locks and using atomic types instead.
    • [ENHANCEMENT]: Scrape: Add a no-default-scrape-port feature flag, which omits or removes any default HTTP (:80) or HTTPS (:443) ports in the target's scrape address.
    • [BUGFIX]: TSDB: In the WAL watcher metrics, expose the type='exemplar' label instead of type='unknown' for exemplar records.
    • [BUGFIX]: TSDB: Fix race condition around allocating series IDs during chunk snapshot loading.

golang-github-QubitProducts-exporter_exporter:

  • CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

grafana:

  • CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

prometheus-blackbox_exporter:

  • CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

prometheus-postgres_exporter:

  • CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

spacecmd:

  • Updated to 4.3.23-1
    • Update translation strings

supportutils-plugin-susemanager-client:

  • Updated to 4.3.3-1
    • Write configured crypto-policy in supportconfig
    • Add cloud and Pay-as-you-go checks

uyuni-common-libs:

  • Updated to 4.3.9-1
    • Workaround for python3-debian bug about collecting control file (bsc#1211525, bsc#1208692)
References

Affected packages

SUSE:Manager Client Tools 12 / golang-github-QubitProducts-exporter_exporter

Package

Name
golang-github-QubitProducts-exporter_exporter
Purl
pkg:rpm/suse/golang-github-QubitProducts-exporter_exporter&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.0-1.12.2

Ecosystem specific

{
    "binaries": [
        {
            "prometheus-blackbox_exporter": "0.24.0-1.23.2",
            "golang-github-prometheus-prometheus": "2.45.0-1.47.3",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.18.2",
            "supportutils-plugin-susemanager-client": "4.3.3-6.27.2",
            "prometheus-postgres_exporter": "0.10.1-1.14.3",
            "golang-github-prometheus-alertmanager": "0.23.0-1.21.2",
            "python2-uyuni-common-libs": "4.3.9-1.36.3",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.12.2",
            "spacecmd": "4.3.23-38.127.3",
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2",
            "grafana": "9.5.5-1.54.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / golang-github-lusitaniae-apache_exporter

Package

Name
golang-github-lusitaniae-apache_exporter
Purl
pkg:rpm/suse/golang-github-lusitaniae-apache_exporter&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.0-1.18.2

Ecosystem specific

{
    "binaries": [
        {
            "prometheus-blackbox_exporter": "0.24.0-1.23.2",
            "golang-github-prometheus-prometheus": "2.45.0-1.47.3",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.18.2",
            "supportutils-plugin-susemanager-client": "4.3.3-6.27.2",
            "prometheus-postgres_exporter": "0.10.1-1.14.3",
            "golang-github-prometheus-alertmanager": "0.23.0-1.21.2",
            "python2-uyuni-common-libs": "4.3.9-1.36.3",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.12.2",
            "spacecmd": "4.3.23-38.127.3",
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2",
            "grafana": "9.5.5-1.54.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / golang-github-prometheus-alertmanager

Package

Name
golang-github-prometheus-alertmanager
Purl
pkg:rpm/suse/golang-github-prometheus-alertmanager&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.23.0-1.21.2

Ecosystem specific

{
    "binaries": [
        {
            "prometheus-blackbox_exporter": "0.24.0-1.23.2",
            "golang-github-prometheus-prometheus": "2.45.0-1.47.3",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.18.2",
            "supportutils-plugin-susemanager-client": "4.3.3-6.27.2",
            "prometheus-postgres_exporter": "0.10.1-1.14.3",
            "golang-github-prometheus-alertmanager": "0.23.0-1.21.2",
            "python2-uyuni-common-libs": "4.3.9-1.36.3",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.12.2",
            "spacecmd": "4.3.23-38.127.3",
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2",
            "grafana": "9.5.5-1.54.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.0-1.27.2

Ecosystem specific

{
    "binaries": [
        {
            "prometheus-blackbox_exporter": "0.24.0-1.23.2",
            "golang-github-prometheus-prometheus": "2.45.0-1.47.3",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.18.2",
            "supportutils-plugin-susemanager-client": "4.3.3-6.27.2",
            "prometheus-postgres_exporter": "0.10.1-1.14.3",
            "golang-github-prometheus-alertmanager": "0.23.0-1.21.2",
            "python2-uyuni-common-libs": "4.3.9-1.36.3",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.12.2",
            "spacecmd": "4.3.23-38.127.3",
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2",
            "grafana": "9.5.5-1.54.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / golang-github-prometheus-prometheus

Package

Name
golang-github-prometheus-prometheus
Purl
pkg:rpm/suse/golang-github-prometheus-prometheus&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.45.0-1.47.3

Ecosystem specific

{
    "binaries": [
        {
            "prometheus-blackbox_exporter": "0.24.0-1.23.2",
            "golang-github-prometheus-prometheus": "2.45.0-1.47.3",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.18.2",
            "supportutils-plugin-susemanager-client": "4.3.3-6.27.2",
            "prometheus-postgres_exporter": "0.10.1-1.14.3",
            "golang-github-prometheus-alertmanager": "0.23.0-1.21.2",
            "python2-uyuni-common-libs": "4.3.9-1.36.3",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.12.2",
            "spacecmd": "4.3.23-38.127.3",
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2",
            "grafana": "9.5.5-1.54.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / grafana

Package

Name
grafana
Purl
pkg:rpm/suse/grafana&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.5.5-1.54.3

Ecosystem specific

{
    "binaries": [
        {
            "prometheus-blackbox_exporter": "0.24.0-1.23.2",
            "golang-github-prometheus-prometheus": "2.45.0-1.47.3",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.18.2",
            "supportutils-plugin-susemanager-client": "4.3.3-6.27.2",
            "prometheus-postgres_exporter": "0.10.1-1.14.3",
            "golang-github-prometheus-alertmanager": "0.23.0-1.21.2",
            "python2-uyuni-common-libs": "4.3.9-1.36.3",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.12.2",
            "spacecmd": "4.3.23-38.127.3",
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2",
            "grafana": "9.5.5-1.54.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / prometheus-blackbox_exporter

Package

Name
prometheus-blackbox_exporter
Purl
pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.24.0-1.23.2

Ecosystem specific

{
    "binaries": [
        {
            "prometheus-blackbox_exporter": "0.24.0-1.23.2",
            "golang-github-prometheus-prometheus": "2.45.0-1.47.3",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.18.2",
            "supportutils-plugin-susemanager-client": "4.3.3-6.27.2",
            "prometheus-postgres_exporter": "0.10.1-1.14.3",
            "golang-github-prometheus-alertmanager": "0.23.0-1.21.2",
            "python2-uyuni-common-libs": "4.3.9-1.36.3",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.12.2",
            "spacecmd": "4.3.23-38.127.3",
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2",
            "grafana": "9.5.5-1.54.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / prometheus-postgres_exporter

Package

Name
prometheus-postgres_exporter
Purl
pkg:rpm/suse/prometheus-postgres_exporter&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.10.1-1.14.3

Ecosystem specific

{
    "binaries": [
        {
            "prometheus-blackbox_exporter": "0.24.0-1.23.2",
            "golang-github-prometheus-prometheus": "2.45.0-1.47.3",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.18.2",
            "supportutils-plugin-susemanager-client": "4.3.3-6.27.2",
            "prometheus-postgres_exporter": "0.10.1-1.14.3",
            "golang-github-prometheus-alertmanager": "0.23.0-1.21.2",
            "python2-uyuni-common-libs": "4.3.9-1.36.3",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.12.2",
            "spacecmd": "4.3.23-38.127.3",
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2",
            "grafana": "9.5.5-1.54.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / spacecmd

Package

Name
spacecmd
Purl
pkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.23-38.127.3

Ecosystem specific

{
    "binaries": [
        {
            "prometheus-blackbox_exporter": "0.24.0-1.23.2",
            "golang-github-prometheus-prometheus": "2.45.0-1.47.3",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.18.2",
            "supportutils-plugin-susemanager-client": "4.3.3-6.27.2",
            "prometheus-postgres_exporter": "0.10.1-1.14.3",
            "golang-github-prometheus-alertmanager": "0.23.0-1.21.2",
            "python2-uyuni-common-libs": "4.3.9-1.36.3",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.12.2",
            "spacecmd": "4.3.23-38.127.3",
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2",
            "grafana": "9.5.5-1.54.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / supportutils-plugin-susemanager-client

Package

Name
supportutils-plugin-susemanager-client
Purl
pkg:rpm/suse/supportutils-plugin-susemanager-client&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.3-6.27.2

Ecosystem specific

{
    "binaries": [
        {
            "prometheus-blackbox_exporter": "0.24.0-1.23.2",
            "golang-github-prometheus-prometheus": "2.45.0-1.47.3",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.18.2",
            "supportutils-plugin-susemanager-client": "4.3.3-6.27.2",
            "prometheus-postgres_exporter": "0.10.1-1.14.3",
            "golang-github-prometheus-alertmanager": "0.23.0-1.21.2",
            "python2-uyuni-common-libs": "4.3.9-1.36.3",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.12.2",
            "spacecmd": "4.3.23-38.127.3",
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2",
            "grafana": "9.5.5-1.54.3"
        }
    ]
}

SUSE:Manager Client Tools 12 / uyuni-common-libs

Package

Name
uyuni-common-libs
Purl
pkg:rpm/suse/uyuni-common-libs&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.9-1.36.3

Ecosystem specific

{
    "binaries": [
        {
            "prometheus-blackbox_exporter": "0.24.0-1.23.2",
            "golang-github-prometheus-prometheus": "2.45.0-1.47.3",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.18.2",
            "supportutils-plugin-susemanager-client": "4.3.3-6.27.2",
            "prometheus-postgres_exporter": "0.10.1-1.14.3",
            "golang-github-prometheus-alertmanager": "0.23.0-1.21.2",
            "python2-uyuni-common-libs": "4.3.9-1.36.3",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.12.2",
            "spacecmd": "4.3.23-38.127.3",
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2",
            "grafana": "9.5.5-1.54.3"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP5 / golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.0-1.27.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP5 / golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.0-1.27.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.5.0-1.27.2"
        }
    ]
}