🛡️ SUSE-EL-9-CLIENT-TOOLS-2024-4019 — golang-github-lusitaniae-apache-exporter (CVE-2023-3978)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for SUSE Manager Client Tools

This update fixes the following issues:

golang-github-lusitaniae-apache_exporter was updated from version 1.0.1 to 1.0.8:

  • Security issues fixed:
  • CVE-2023-3978: Fixed security bug in x/net dependency in version 1.0.2 (bsc#1213933)
  • Bugs fixed:
  • Require Go 1.20 when building for RedHat derivatives
  • Version 1.0.8 (bsc#1227341):

+ Update prometheus/client_golang to version 1.19.1

+ Update x/net to version 0.23.0

  • Version 1.0.7:

+ Update protobuf to version 1.33.0

+ Update prometheus/client_golang to version 1.19.0

+ Update prometheus/common to version 0.46.0

+ Standardize landing page

  • Version 1.0.6:

+ Update prometheus/exporter-toolkit to version 0.11.0

+ Update prometheus/client_golang to version 1.18.0

+ Added User-Agent header

  • Version 1.0.4:

+ Update x/crypto to version 0.17.0

+ Update alecthomas/kingpin/v2 to version 2.4.0

+ Update prometheus/common to version 0.45.0

  • Version 1.0.3:

+ Update prometheus/client_golang to version 1.17.0

+ Update x/net 0.17.0

  • Version 1.0.1:

+ Update prometheus/exporter-toolkit to version 0.10.0

+ Update prometheus/common to version 0.44.0

+ Update prometheus/client_golang to version 1.16.0

scap-security-guide was updated from version 0.1.73 to 0.1.74:

  • Version 0.1.74 (jsc#ECO-3319):
  • Added Amazon Linux 2023 product
  • Introduce new remediation type Kickstart
  • Make PAM macros more flexible to variables
  • Remove Debian 10 Product
  • Remove Red Hat Enterprise Linux 7 product
  • Update CIS RHEL9 control file to v2.0.0

spacecmd was updated from version 5.0.9-0 to 5.0.10-0:

  • Version 5.0.10-0:
  • Speed up softwarechannel_removepackages (bsc#1227606)
  • Fixed error in 'kickstart_delete' when using wildcards

(bsc#1227578)

  • Spacecmd bootstrap now works with specified port (bsc#1229437)
  • Fixed sls backup creation as directory with spacecmd (bsc#1230745)

uyuni-tools was updated from version 0.1.21-0 to 0.1.23-0:

  • Version 0.1.23-0:
  • Ensure namespace is defined in all kubernetes commands
  • Use SCC credentials to authenticate against registry.suse.com

for kubernetes (bsc#1231157)

  • Fixed namespace usage on mgrctl cp command
  • Version 0.1.22-0:
  • Set projectId also for test packages/images
  • mgradm migration should not pull Confidential Computing and Hub

image is replicas == 0 (bsc#1229432, bsc#1230136)

  • Do not allow SUSE Manager downgrade
  • Prevent completion issue when /var/log/uyuni-tools.log is missing
  • Fixed proxy shared volume flag
  • During migration, exclude mgr-sync configuration file (bsc#1228685)
  • Migrate from PostgreSQL 14 to PostgreSQL 16 pg_hba.conf and

postgresql.conf files (bsc#1231206)

  • During migration, handle empty autoinstallation path (bsc#1230285)
  • During migration, handle symlinks (bsc#1230288)
  • During migration, trust the remote sender's file list (bsc#1228424)
  • Use SCC flags during podman pull
  • Restore SELinux permission after migration (bsc#1229501)
  • Share volumes between containers (bsc#1223142)
  • Save supportconfig in current directory (bsc#1226759)
  • Fixed error code handling on reinstallation (bsc#1230139)
  • Fixed creation of first user and organization
  • Added missing variable quotes for install vars (bsc#1229108)
  • Added API login and logout calls to allow persistent login

Affected software

SUSE-EL-9-CLIENT-TOOLS-2024-4019 is recorded against 4 packages.

  • golang-github-lusitaniae-apache-exporter (fixed in 1.0.8-1.14.1)
  • scap-security-guide (fixed in 0.1.74-1.29.1)
  • spacecmd (fixed in 5.0.10-1.41.1)
  • uyuni-tools (fixed in 0.1.23-1.11.1)

Timeline and source

Published on 18 November 2024 and last revised on 24 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-11-18
Updated 2026-08-20
Modified 2026-07-24
Fix URL N/A

Affected Packages

Software From version Fixed in
golang-github-lusitaniae-apache-exporter 1.0.8-1.14.1
scap-security-guide 0.1.74-1.29.1
spacecmd 5.0.10-1.41.1
uyuni-tools 0.1.23-1.11.1

References

Free Vulnerability Check

Is your site affected by SUSE-EL-9-CLIENT-TOOLS-2024-4019?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-EL-9-CLIENT-TOOLS-2024-4019 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2024