🛡️ SUSE-SU-2021:3561-1 — cobbler (CVE-2021-21996 +1 more)
Description
Security update for SUSE Manager Server 4.2
This update fixes the following issues:
cobbler:
- Fixed modify_setting test to complete successfully
hub-xmlrpc-api:
- Use rpm systemd macro to restart service in replace of systemctl
patterns-suse-manager:
- Virtualization-host-formula was renamed to virtualization-formulas
py26-compat-salt:
- Exclude the full path of a download URL to prevent injection of malicious code (bsc#1190265, CVE-2021-21996)
py26-compat-tornado:
- Added compatibility to Enterprise Linux 8
py27-compat-salt:
- Fix the regression of docker_container state module
- Support querying for JSON data in external sql pillar
- Exclude the full path of a download URL to prevent injection of malicious code (bsc#1190265, CVE-2021-21996)
- Fix wrong relative paths resolution with Jinja renderer when importing subdirectories
spacecmd:
- Version 4.2.13-1
- Update translation strings
- configchannel_updatefile handles directory properly (bsc#1190512)
- Add schedule_archivecompleted to mass archive actions (bsc#1181223)
- Remove whoami from the list of unauthenticated commands (bsc#1188977)
spacewalk-admin:
- Version 4.2.9-1
- Fix setup with rhn-config-satellite (bsc#1190300)
- Allow admins to modify only spacewalk config files with
rhn-config-satellite.pl (bsc#1190040) (CVE-2021-40348)
spacewalk-backend:
- Version 4.2.17-1
- Update translations strings
- handle download of metadata filesnames with checksums (bsc#1188315)
- Sanitize cached filename for custom SSL certs used by reposync (bsc#1190751)
spacewalk-certs-tools:
- Version 4.2.13-1
- add GPG keys using apt-key on debian machines (bsc#1187998)
spacewalk-client-tools:
- Version 4.2.14-1
- Update translation strings
spacewalk-java:
- Version 4.2.30-1
- Fix datetime format parsing with moment (bsc#1191348)
- Version 4.2.29-1
- Update translation strings
- fix logging of the spark framework and map requests to media.1
directory in the download controller (bsc#1189933)
- Add 'Last build date' column to CLM project list (jsc#PM-2644)
(jsc#SUMA-61)
- Improve exception handling and logging for mgr-libmod calls
- Add checksums to repository metadata filenames (bsc#1188315)
- Fix ISE in product migration if base product is missing (bsc#1190151)
- use TLSv1.3 if it is a supported Protocol
- Adapt auto errata update to respect maintenance windows
- Adapt auto errata update to skip during CLM build (bsc#1189609)
- add CentOS 7/8 aarch64
- add Oracle Linux 7/8 aarch64
- add Rocky Linux 8 aarch64
- add AlmaLinux 8 aarch64
- add Amazon Linux 2 aarch64
- Add new endpoints to saltkeys API: acceptedList, pendingList, rejectedList,
deniedList, accept and reject
- fix ISE in SSM when scheduling patches on multiple systems (bsc#1190396, bsc#1190275)
- Add 'Flush cache' option to Ansible playbook execution
(bsc#1190405)
- Update kernel live patch version on minion startup (bsc#1190276)
- Allow getting all completed actions via XMLRPC without display limit (bsc#1181223)
- Support syncing patches with advisory status 'pending' (bsc#1190455)
- Add XMLRPC API to force refreshing pillar data (bsc#1190123)
- Add missing string on XCCDF scan results (bsc#1190164)
- Ignore duplicates in 'pkg.installed' result when applying patches (bsc#1187572)
- Improved timezone support
- implement package locking for salt minions
spacewalk-utils:
- Version 4.2.14-1
- When renaming: don't regenerate CA, allow using third-party
certificate and trigger pillar refresh (bsc#1190123)
spacewalk-web:
- Version 4.2.23-1
- Fix datetime format parsing with moment (bsc#1191348)
- Version 4.2.22-1
- Add 'Last build date' column to CLM project list (jsc#PM-2644)
(jsc#SUMA-61)
- Fix 'Type' input in CLM source edit form (bsc#1190820)
- Add 'Flush cache' checkbox to Ansible playbook execution page
(bsc#1190405)
- Fix the VM creation and editing submit button action (bsc#1190602)
- Improved timezone support
- Enhance the default base channel help message (bsc#1171520)
subscription-matcher:
- Version 0.27
- update subscription rules for new SKUs (bsc#1189818)
supportutils-plugin-susemanager:
- Version 4.2.3-1
- detect broken symlinks in tomcat, taskomatic and search daemon
susemanager:
- Version 4.2.25-1
- Add python-mako, python-gnupg and gnupg1 to the Debian 9 bootstrap repository
so bootstrapping without any enabled repositories is possible (bsc#1191898)
- Fix syntax error on migration script (bsc#1191551)
- Add aarch64 bootstrap repositories for CentOS 7/8, Oracle Linux 7/8,
Rocky Linux8, AlmaLinux8, Amazon Linux 2 and openSUSE Leap 15.3
- Add the gnupg package for ubuntu which is then needed by apt-key (bsc#1187998)
- Add SLE 15 SAP Product ID to SLE15 bootstrap repositories, as
it is required to get python3-M2Crypto (bsc#1189422)
susemanager-doc-indexes:
- Added aarch64 support for selection of clients in the Installation
Affected software
SUSE-SU-2021:3561-1 is recorded against 24 packages.
- cobbler (fixed in 3.1.2-5.11.1)
- hub-xmlrpc-api (fixed in 0.7-3.3.3)
- inter-server-sync (fixed in 0.0.5-8.6.3)
- patterns-suse-manager (fixed in 4.2-4.3.1)
- py26-compat-salt (fixed in 2016.11.10-11.28.9.1)
- py26-compat-tornado (fixed in 4.2.1-3.3.1)
- py27-compat-salt (fixed in 3000.3-7.7.11.1)
- spacecmd (fixed in 4.2.13-4.9.1)
- spacewalk-admin (fixed in 4.2.9-3.6.2)
- spacewalk-backend (fixed in 4.2.17-4.9.3)
- spacewalk-certs-tools (fixed in 4.2.13-3.9.2)
- spacewalk-client-tools (fixed in 4.2.14-4.9.3)
- spacewalk-java (fixed in 4.2.30-3.14.4)
- spacewalk-utils (fixed in 4.2.14-3.9.3)
- spacewalk-web (fixed in 4.2.23-3.9.3)
- subscription-matcher (fixed in 0.27-6.3.1)
- supportutils-plugin-susemanager (fixed in 4.2.3-3.3.2)
- susemanager (fixed in 4.2.25-3.13.1)
- susemanager-doc-indexes (fixed in 4.2-12.11.3)
- susemanager-docs-en (fixed in 4.2-12.11.1)
- susemanager-schema (fixed in 4.2.18-3.9.3)
- susemanager-sls (fixed in 4.2.18-3.11.1)
- susemanager-sync-data (fixed in 4.2.9-3.9.1)
- virtualization-formulas (fixed in 0.6.1-8.3.1)
Timeline and source
Published on 27 October 2021 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| cobbler | — | 3.1.2-5.11.1 |
| hub-xmlrpc-api | — | 0.7-3.3.3 |
| inter-server-sync | — | 0.0.5-8.6.3 |
| patterns-suse-manager | — | 4.2-4.3.1 |
| py26-compat-salt | — | 2016.11.10-11.28.9.1 |
| py26-compat-tornado | — | 4.2.1-3.3.1 |
| py27-compat-salt | — | 3000.3-7.7.11.1 |
| spacecmd | — | 4.2.13-4.9.1 |
| spacewalk-admin | — | 4.2.9-3.6.2 |
| spacewalk-backend | — | 4.2.17-4.9.3 |
| spacewalk-certs-tools | — | 4.2.13-3.9.2 |
| spacewalk-client-tools | — | 4.2.14-4.9.3 |
| spacewalk-java | — | 4.2.30-3.14.4 |
| spacewalk-utils | — | 4.2.14-3.9.3 |
| spacewalk-web | — | 4.2.23-3.9.3 |
| subscription-matcher | — | 0.27-6.3.1 |
| supportutils-plugin-susemanager | — | 4.2.3-3.3.2 |
| susemanager | — | 4.2.25-3.13.1 |
| susemanager-doc-indexes | — | 4.2-12.11.3 |
| susemanager-docs-en | — | 4.2-12.11.1 |
| susemanager-schema | — | 4.2.18-3.9.3 |
| susemanager-sls | — | 4.2.18-3.11.1 |
| susemanager-sync-data | — | 4.2.9-3.9.1 |
| virtualization-formulas | — | 0.6.1-8.3.1 |
References
Similar Threats
- Critical OESA-2025-1411
- Critical OESA-2025-1412
- Critical CVE-2024-47533
- High CVE-2008-6954
- High CVE-2010-2235
Free Vulnerability Check
Is your site affected by SUSE-SU-2021:3561-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2021:3561-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.