SUSE-SU-2023:3875-1

Source
https://www.suse.com/support/update/announcement/2023/suse-su-20233875-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3875-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2023:3875-1
Related
Published
2023-09-28T11:45:38Z
Modified
2023-09-28T11:45:38Z
Summary
Security update for SUSE Manager Client Tools
Details

This update fixes the following issues:

golang-github-lusitaniae-apache_exporter:

  • Security issues fixed:
    • CVE-2022-32149: Fix denial of service vulnerability (bsc#1204501)
    • CVE-2022-41723: Fix uncontrolled resource consumption (bsc#1208270)
    • CVE-2022-46146: Fix authentication bypass vulnarability (bsc#1208046)
  • Changes and bugs fixed:
    • Updated to 1.0.0 (jsc#PED-5405)
      • Improved flag parsing
      • Added support for custom headers
    • Changes from 0.13.1
      • Fix panic caused by missing flagConfig options
    • Changes from 0.11.0 (jsc#SLE-24791)
      • Add TLS support
      • Switch to logger, please check --log.level and --log.format flags
    • Changes from 0.10.1
      • Bugfix: Reset ProxyBalancer metrics on each scrape to remove stale data
    • Changes from 0.10.0
      • Add Apache Proxy and other metrics
    • Changes from 0.8.0
      • Change commandline flags
      • Add metrics: Apache version, request duration total
    • Changes from 0.7.0
      • Handle OS TERM signals
    • Changes from 0.6.0
      • Add option to override host name
    • Added support for Red Hat Enterprise Linux
    • Added AppArmor profile
    • Added sandboxing options to systemd service unit
    • Build using promu
    • Build with Go 1.19
    • Exclude s390 architecture

golang-github-prometheus-node_exporter:

  • CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

golang-github-QubitProducts-exporter_exporter:

  • CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

prometheus-postgres_exporter:

  • CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version.

scap-security-guide:

  • Updated to 0.1.69 (jsc#ECO-3319)
    • Introduce a JSON build manifest
    • Introduce a script to compare ComplianceAsCode versions
    • Introduce CCN profiles for Red Hat Enterprise Linux 9
    • Map rules to components
    • products/anolis23: supports Anolis OS 23
    • Render components to HTML
    • Store rendered control files
    • Test and use rules to components mapping
    • Use distributed product properties
  • Revert patch that breaks the SLE hardening (bsc#1213691)
  • Changes from 0.1.68 (jsc#ECO-3319)
    • Bump OL8 STIG version to V1R6
    • Introduce a Product class, make the project work with it
    • Introduce Fedora and Firefox CaC profiles for common workstation users
    • OL7 DISA STIG v2r11 update
    • Publish rendered policy artifacts
    • Update ANSSI BP-028 to version 2.0
  • Changes from 0.1.67 (jsc#ECO-3319)
    • Add utils/controlrefcheck.py
    • Red Hat Enterprise Linux 9 STIG Update Q1 2023
    • Include warning for NetworkManager keyfiles in Red Hat Enterprise Linux 9
    • OL7 stig v2r10 update
    • Bump version of OL8 STIG to V1R5
  • Various enhancements to SLE profiles

spacecmd:

  • Updated to 4.3.23-1
    • Update translation strings
References

Affected packages

SUSE:EL-9:Update:Products:ManagerTools:Update / golang-github-QubitProducts-exporter_exporter

Package

Name
golang-github-QubitProducts-exporter_exporter
Purl
purl:rpm/suse/golang-github-QubitProducts-exporter_exporter&distro=SUSE:EL-9:Update:Products:ManagerTools:Update

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.0-1.6.1

Ecosystem specific

{
    "binaries": [
        {
            "scap-security-guide-ubuntu": "0.1.69-1.12.2",
            "scap-security-guide-debian": "0.1.69-1.12.2",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "prometheus-postgres_exporter": "0.10.1-1.9.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "scap-security-guide": "0.1.69-1.12.2"
        }
    ]
}

SUSE:EL-9:Update:Products:ManagerTools:Update / golang-github-lusitaniae-apache_exporter

Package

Name
golang-github-lusitaniae-apache_exporter
Purl
purl:rpm/suse/golang-github-lusitaniae-apache_exporter&distro=SUSE:EL-9:Update:Products:ManagerTools:Update

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.0-1.8.1

Ecosystem specific

{
    "binaries": [
        {
            "scap-security-guide-ubuntu": "0.1.69-1.12.2",
            "scap-security-guide-debian": "0.1.69-1.12.2",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "prometheus-postgres_exporter": "0.10.1-1.9.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "scap-security-guide": "0.1.69-1.12.2"
        }
    ]
}

SUSE:EL-9:Update:Products:ManagerTools:Update / golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
purl:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE:EL-9:Update:Products:ManagerTools:Update

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.0-1.9.2

Ecosystem specific

{
    "binaries": [
        {
            "scap-security-guide-ubuntu": "0.1.69-1.12.2",
            "scap-security-guide-debian": "0.1.69-1.12.2",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "prometheus-postgres_exporter": "0.10.1-1.9.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "scap-security-guide": "0.1.69-1.12.2"
        }
    ]
}

SUSE:EL-9:Update:Products:ManagerTools:Update / prometheus-postgres_exporter

Package

Name
prometheus-postgres_exporter
Purl
purl:rpm/suse/prometheus-postgres_exporter&distro=SUSE:EL-9:Update:Products:ManagerTools:Update

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.10.1-1.9.2

Ecosystem specific

{
    "binaries": [
        {
            "scap-security-guide-ubuntu": "0.1.69-1.12.2",
            "scap-security-guide-debian": "0.1.69-1.12.2",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "prometheus-postgres_exporter": "0.10.1-1.9.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "scap-security-guide": "0.1.69-1.12.2"
        }
    ]
}

SUSE:EL-9:Update:Products:ManagerTools:Update / scap-security-guide

Package

Name
scap-security-guide
Purl
purl:rpm/suse/scap-security-guide&distro=SUSE:EL-9:Update:Products:ManagerTools:Update

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.69-1.12.2

Ecosystem specific

{
    "binaries": [
        {
            "scap-security-guide-ubuntu": "0.1.69-1.12.2",
            "scap-security-guide-debian": "0.1.69-1.12.2",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "prometheus-postgres_exporter": "0.10.1-1.9.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "scap-security-guide": "0.1.69-1.12.2"
        }
    ]
}

SUSE:EL-9:Update:Products:ManagerTools:Update / spacecmd

Package

Name
spacecmd
Purl
purl:rpm/suse/spacecmd&distro=SUSE:EL-9:Update:Products:ManagerTools:Update

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.23-1.18.2

Ecosystem specific

{
    "binaries": [
        {
            "scap-security-guide-ubuntu": "0.1.69-1.12.2",
            "scap-security-guide-debian": "0.1.69-1.12.2",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "prometheus-postgres_exporter": "0.10.1-1.9.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "scap-security-guide": "0.1.69-1.12.2"
        }
    ]
}

SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS / golang-github-QubitProducts-exporter_exporter

Package

Name
golang-github-QubitProducts-exporter_exporter
Purl
purl:rpm/suse/golang-github-QubitProducts-exporter_exporter&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.0-1.6.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "prometheus-postgres_exporter": "0.10.1-1.9.2"
        }
    ]
}

SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS / golang-github-lusitaniae-apache_exporter

Package

Name
golang-github-lusitaniae-apache_exporter
Purl
purl:rpm/suse/golang-github-lusitaniae-apache_exporter&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.0-1.8.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "prometheus-postgres_exporter": "0.10.1-1.9.2"
        }
    ]
}

SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS / golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
purl:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.0-1.9.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "prometheus-postgres_exporter": "0.10.1-1.9.2"
        }
    ]
}

SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS / prometheus-postgres_exporter

Package

Name
prometheus-postgres_exporter
Purl
purl:rpm/suse/prometheus-postgres_exporter&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.10.1-1.9.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "prometheus-postgres_exporter": "0.10.1-1.9.2"
        }
    ]
}

SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS / scap-security-guide

Package

Name
scap-security-guide
Purl
purl:rpm/suse/scap-security-guide&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.69-1.12.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "prometheus-postgres_exporter": "0.10.1-1.9.2"
        }
    ]
}

SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS / spacecmd

Package

Name
spacecmd
Purl
purl:rpm/suse/spacecmd&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.23-1.18.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-lusitaniae-apache_exporter": "1.0.0-1.8.1",
            "scap-security-guide-redhat": "0.1.69-1.12.2",
            "golang-github-QubitProducts-exporter_exporter": "0.4.0-1.6.1",
            "spacecmd": "4.3.23-1.18.2",
            "golang-github-prometheus-node_exporter": "1.5.0-1.9.2",
            "prometheus-postgres_exporter": "0.10.1-1.9.2"
        }
    ]
}