🛡️ SUSE-SU-2021:3170-1 — branch-network-formula (CVE-2021-40323 +2 more)
Description
Security update for SUSE Manager Server 4.2
This update fixes the following issues:
branch-network-formula:
- Use kernel parameters from PXE formula also for local boot
cobbler - security issues fixed:
- CVE-2021-40323: Fixed an arbitrary file disclosure/Template Injection (bsc#1189458)
- CVE-2021-40324: Fixed an arbitrary file write (bsc#1189458)
- CVE-2021-40325: Fixed a problem with the token validation (bsc#1189458)
- Please note that with these changes, a valid log data from Anamon (Red Hat Autoinstallation Process) uploaded to
cobbler may be rejected:
cpu-mitigations-formula:
- Add SLES 15 SP3 and openSUSE Leap 15.3 to supported versions
openvpn-formula:
- Changed package to noarch.
prometheus-exporters-formula:
- Fix formula data migration with missing exporter configuration (bsc#1188136)
py26-compat-salt:
- Fix error handling in openscap module (bsc#1188647)
- Define license macro as doc in spec file if not existing
py27-compat-salt:
- Add missing aarch64 to rpm package architectures
- Consolidate some state requisites (bsc#1188641)
- Fix failing unit test for systemd
- Fix error handling in openscap module (bsc#1188647)
- Better handling of bad public keys from minions (bsc#1189040)
- Define license macro as doc in spec file if not existing
saltboot-formula:
- Use kernel parameters from PXE formula also for local boot
spacecmd:
- Update translation strings
- Make schedule_deletearchived to get all actions without display limit
- Allow passing a date limit for schedule_deletearchived on spacecmd (bsc#1181223)
- Use correct API endpoint in list_proxies (bsc#1188042)
- Add schedule_deletearchived to bulk delete archived actions (bsc#1181223)
spacewalk-backend:
- Update translation strings
- Fix typo 'verfication' instead of 'verification'
spacewalk-certs-tools:
- Prepare the bootstrap script generator for Rocky Linux 8
spacewalk-client-tools:
- Update translation strings
spacewalk-java:
- Show AppStreams tab just for modular channels
- Fix Json null comparison in virtual network info parsing (bsc#1189167)
- Update translation strings
- 'AppStreams with defaults' filter template in CLM
- Add a link to OS image store dir in image list page
- Do not log XMLRPC fault exceptions as errors (bsc#1188853)
- XMLRPC: Add call for listing application monitoring endpoints
- AppStreams tab for modular channels
- Link to CLM filter creation from system details page
- Allow getting all archived actions via XMLRPC without display limit (bsc#1181223)
- Fix NPE when no redhat info could be fetched
- Java enablement for Rocky Linux 8
- Delete ActionChains when the last action is a Reboot and it completes (bsc#1188163)
- Properly handle virtual networks without defined bridge (bsc#1189167)
- Mark SSH minion actions when they're picked up (bsc#1188505)
- Add UEFI support for VM creation / editing
- Add virt-tuner templates to VM creation
- Fix cleanup always being executed on delete system (bsc#1189011)
- Warning in Overview page for SLE Micro system (bsc#1188551)
- Add support for Kiwi options
- Ensure XMLRPC returns 'issue_date' in ISO format when listing erratas (bsc#1188260)
- Fix NullPointerException in HardwareMapper.getUpdatedGuestMemory
- Fix entitlements not being updated during system transfer (bsc#1188032)
- Simplify the VM creation action in DB
- Get CPU data for AArch64
- Handle virtual machines running on pacemaker cluster
- Refresh virtual host pillar to clear the virtpoller beacon (bsc#1188393)
- Add Beijing timezone to selectable timezones (bsc#1188193)
- Fix updating primary net interface on hardware refresh (bsc#1188400)
- Fix issues when removing archived actions using XMLRPC api (bsc#1181223)
- Readable error when 'mgr-sync add channel' is called with a no-existing label (bsc#1173143)
spacewalk-setup:
- Enable logging for salt SSH
- Increase max size for uploaded files to Salt master
spacewalk-utils:
- Add Rocky Linux 8 repositories
spacewalk-web:
- Don't capitalize acronyms
- Update translation strings
- 'AppStreams with defaults' filter template in CLM
- Add a link to OS image store dir in image list page
- Link to CLM filter creation from system details page
- Expose UEFI parameters in the VM creation/editing pages
- Add virt-tuner templates to VM creation
- Fix cleanup always being executed on delete system (bsc#1189011)
- Add support for Kiwi options
- Fix virtualization guests to handle null HostInfo
- Compare lowercase CPU arch with libvirt domain capabilities
- Refresh JWT virtual console token before it expires
- Handle virtual machines running on pacemaker cluster
susemanager:
- Abort migration if data_directory is defined at the PostgreSQL
configuration file
- Update translation strings
- Add bootstrap repository definitions for Rocky Linux 8
susemanager-build-keys:
- Add Debian 11
- Add Rocky Linux 8
susemanager-doc-indexes:
- Added SUSE Linux Enterprise 15 Service Pack 3 to clients list
- Add information about pam service name limitations
- Add
Affected software
SUSE-SU-2021:3170-1 is recorded against 24 packages.
- branch-network-formula (fixed in 0.1.1628156312.dbd0dec-3.3.1)
- cobbler (fixed in 3.1.2-5.8.1)
- cpu-mitigations-formula (fixed in 0.4.0-3.3.1)
- inter-server-sync (fixed in 0.0.5-8.3.2)
- openvpn-formula (fixed in 0.1.2-3.3.1)
- prometheus-exporters-formula (fixed in 1.0.3-3.6.1)
- py26-compat-salt (fixed in 2016.11.10-11.28.6.1)
- py27-compat-salt (fixed in 3000.3-7.7.8.1)
- saltboot-formula (fixed in 0.1.1628156312.dbd0dec-3.3.1)
- spacecmd (fixed in 4.2.12-4.6.2)
- spacewalk-backend (fixed in 4.2.16-4.6.3)
- spacewalk-certs-tools (fixed in 4.2.12-3.6.2)
- spacewalk-client-tools (fixed in 4.2.13-4.6.3)
- spacewalk-java (fixed in 4.2.28-3.11.5)
- spacewalk-setup (fixed in 4.2.8-3.6.1)
- spacewalk-utils (fixed in 4.2.13-3.6.1)
- spacewalk-web (fixed in 4.2.21-3.6.3)
- susemanager (fixed in 4.2.22-3.6.1)
- susemanager-build-keys (fixed in 15.3.5-3.3.1)
- susemanager-doc-indexes (fixed in 4.2-12.8.1)
- susemanager-docs-en (fixed in 4.2-12.8.1)
- susemanager-schema (fixed in 4.2.17-3.6.2)
- susemanager-sls (fixed in 4.2.16-3.6.1)
- susemanager-sync-data (fixed in 4.2.8-3.6.1)
Timeline and source
Published on 20 September 2021 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| branch-network-formula | — | 0.1.1628156312.dbd0dec-3.3.1 |
| cobbler | — | 3.1.2-5.8.1 |
| cpu-mitigations-formula | — | 0.4.0-3.3.1 |
| inter-server-sync | — | 0.0.5-8.3.2 |
| openvpn-formula | — | 0.1.2-3.3.1 |
| prometheus-exporters-formula | — | 1.0.3-3.6.1 |
| py26-compat-salt | — | 2016.11.10-11.28.6.1 |
| py27-compat-salt | — | 3000.3-7.7.8.1 |
| saltboot-formula | — | 0.1.1628156312.dbd0dec-3.3.1 |
| spacecmd | — | 4.2.12-4.6.2 |
| spacewalk-backend | — | 4.2.16-4.6.3 |
| spacewalk-certs-tools | — | 4.2.12-3.6.2 |
| spacewalk-client-tools | — | 4.2.13-4.6.3 |
| spacewalk-java | — | 4.2.28-3.11.5 |
| spacewalk-setup | — | 4.2.8-3.6.1 |
| spacewalk-utils | — | 4.2.13-3.6.1 |
| spacewalk-web | — | 4.2.21-3.6.3 |
| susemanager | — | 4.2.22-3.6.1 |
| susemanager-build-keys | — | 15.3.5-3.3.1 |
| susemanager-doc-indexes | — | 4.2-12.8.1 |
| susemanager-docs-en | — | 4.2-12.8.1 |
| susemanager-schema | — | 4.2.17-3.6.2 |
| susemanager-sls | — | 4.2.16-3.6.1 |
| susemanager-sync-data | — | 4.2.8-3.6.1 |
References
Similar Threats
- Unknown SUSE-RU-2023:2566-1
- Unknown SUSE-SU-2021:3170-1
Free Vulnerability Check
Is your site affected by SUSE-SU-2021:3170-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2021:3170-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.