openSUSE-SU-2024:0370-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0370-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2024:0370-1
Related
Published
2024-11-21T11:21:20Z
Modified
2024-11-21T11:21:20Z
Summary
Security update for cobbler
Details

This update for cobbler fixes the following issues:

Update to 3.3.7

  • Security: Fix issue that allowed anyone to connect to the API as admin (CVE-2024-47533, boo#1231332)
  • bind - Fix bug that prevents cname entries from being generated successfully
  • Fix build on RHEL9 based distributions (fence-agents-all split)
  • Fix for Windows systems
  • Docs: Add missing dependencies for source installation
  • Fix issue that prevented systems from being synced when the profile was edited
References

Affected packages

SUSE:Package Hub 15 SP6 / cobbler

Package

Name
cobbler
Purl
pkg:rpm/suse/cobbler&distro=SUSE%20Package%20Hub%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3.7-bp156.2.6.1

Ecosystem specific

{
    "binaries": [
        {
            "cobbler": "3.3.7-bp156.2.6.1",
            "cobbler-tests-containers": "3.3.7-bp156.2.6.1",
            "cobbler-tests": "3.3.7-bp156.2.6.1"
        }
    ]
}

openSUSE:Leap 15.6 / cobbler

Package

Name
cobbler
Purl
pkg:rpm/opensuse/cobbler&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3.7-bp156.2.6.1

Ecosystem specific

{
    "binaries": [
        {
            "cobbler": "3.3.7-bp156.2.6.1",
            "cobbler-tests-containers": "3.3.7-bp156.2.6.1",
            "cobbler-tests": "3.3.7-bp156.2.6.1"
        }
    ]
}