🛡️ SUSE-SU-2021:3561-1 — cobbler (CVE-2021-21996 +1 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for SUSE Manager Server 4.2

This update fixes the following issues:

cobbler:

  • Fixed modify_setting test to complete successfully

hub-xmlrpc-api:

  • Use rpm systemd macro to restart service in replace of systemctl

patterns-suse-manager:

  • Virtualization-host-formula was renamed to virtualization-formulas

py26-compat-salt:

  • Exclude the full path of a download URL to prevent injection of malicious code (bsc#1190265, CVE-2021-21996)

py26-compat-tornado:

  • Added compatibility to Enterprise Linux 8

py27-compat-salt:

  • Fix the regression of docker_container state module
  • Support querying for JSON data in external sql pillar
  • Exclude the full path of a download URL to prevent injection of malicious code (bsc#1190265, CVE-2021-21996)
  • Fix wrong relative paths resolution with Jinja renderer when importing subdirectories

spacecmd:

  • Version 4.2.13-1
  • Update translation strings
  • configchannel_updatefile handles directory properly (bsc#1190512)
  • Add schedule_archivecompleted to mass archive actions (bsc#1181223)
  • Remove whoami from the list of unauthenticated commands (bsc#1188977)

spacewalk-admin:

  • Version 4.2.9-1
  • Fix setup with rhn-config-satellite (bsc#1190300)
  • Allow admins to modify only spacewalk config files with

rhn-config-satellite.pl (bsc#1190040) (CVE-2021-40348)

spacewalk-backend:

  • Version 4.2.17-1
  • Update translations strings
  • handle download of metadata filesnames with checksums (bsc#1188315)
  • Sanitize cached filename for custom SSL certs used by reposync (bsc#1190751)

spacewalk-certs-tools:

  • Version 4.2.13-1
  • add GPG keys using apt-key on debian machines (bsc#1187998)

spacewalk-client-tools:

  • Version 4.2.14-1
  • Update translation strings

spacewalk-java:

  • Version 4.2.30-1
  • Fix datetime format parsing with moment (bsc#1191348)
  • Version 4.2.29-1
  • Update translation strings
  • fix logging of the spark framework and map requests to media.1

directory in the download controller (bsc#1189933)

  • Add 'Last build date' column to CLM project list (jsc#PM-2644)

(jsc#SUMA-61)

  • Improve exception handling and logging for mgr-libmod calls
  • Add checksums to repository metadata filenames (bsc#1188315)
  • Fix ISE in product migration if base product is missing (bsc#1190151)
  • use TLSv1.3 if it is a supported Protocol
  • Adapt auto errata update to respect maintenance windows
  • Adapt auto errata update to skip during CLM build (bsc#1189609)
  • add CentOS 7/8 aarch64
  • add Oracle Linux 7/8 aarch64
  • add Rocky Linux 8 aarch64
  • add AlmaLinux 8 aarch64
  • add Amazon Linux 2 aarch64
  • Add new endpoints to saltkeys API: acceptedList, pendingList, rejectedList,

deniedList, accept and reject

  • fix ISE in SSM when scheduling patches on multiple systems (bsc#1190396, bsc#1190275)
  • Add 'Flush cache' option to Ansible playbook execution

(bsc#1190405)

  • Update kernel live patch version on minion startup (bsc#1190276)
  • Allow getting all completed actions via XMLRPC without display limit (bsc#1181223)
  • Support syncing patches with advisory status 'pending' (bsc#1190455)
  • Add XMLRPC API to force refreshing pillar data (bsc#1190123)
  • Add missing string on XCCDF scan results (bsc#1190164)
  • Ignore duplicates in 'pkg.installed' result when applying patches (bsc#1187572)
  • Improved timezone support
  • implement package locking for salt minions

spacewalk-utils:

  • Version 4.2.14-1
  • When renaming: don't regenerate CA, allow using third-party

certificate and trigger pillar refresh (bsc#1190123)

spacewalk-web:

  • Version 4.2.23-1
  • Fix datetime format parsing with moment (bsc#1191348)
  • Version 4.2.22-1
  • Add 'Last build date' column to CLM project list (jsc#PM-2644)

(jsc#SUMA-61)

  • Fix 'Type' input in CLM source edit form (bsc#1190820)
  • Add 'Flush cache' checkbox to Ansible playbook execution page

(bsc#1190405)

  • Fix the VM creation and editing submit button action (bsc#1190602)
  • Improved timezone support
  • Enhance the default base channel help message (bsc#1171520)

subscription-matcher:

  • Version 0.27
  • update subscription rules for new SKUs (bsc#1189818)

supportutils-plugin-susemanager:

  • Version 4.2.3-1
  • detect broken symlinks in tomcat, taskomatic and search daemon

susemanager:

  • Version 4.2.25-1
  • Add python-mako, python-gnupg and gnupg1 to the Debian 9 bootstrap repository

so bootstrapping without any enabled repositories is possible (bsc#1191898)

  • Fix syntax error on migration script (bsc#1191551)
  • Add aarch64 bootstrap repositories for CentOS 7/8, Oracle Linux 7/8,

Rocky Linux8, AlmaLinux8, Amazon Linux 2 and openSUSE Leap 15.3

  • Add the gnupg package for ubuntu which is then needed by apt-key (bsc#1187998)
  • Add SLE 15 SAP Product ID to SLE15 bootstrap repositories, as

it is required to get python3-M2Crypto (bsc#1189422)

susemanager-doc-indexes:

  • Added aarch64 support for selection of clients in the Installation

Affected software

SUSE-SU-2021:3561-1 is recorded against 24 packages.

  • cobbler (fixed in 3.1.2-5.11.1)
  • hub-xmlrpc-api (fixed in 0.7-3.3.3)
  • inter-server-sync (fixed in 0.0.5-8.6.3)
  • patterns-suse-manager (fixed in 4.2-4.3.1)
  • py26-compat-salt (fixed in 2016.11.10-11.28.9.1)
  • py26-compat-tornado (fixed in 4.2.1-3.3.1)
  • py27-compat-salt (fixed in 3000.3-7.7.11.1)
  • spacecmd (fixed in 4.2.13-4.9.1)
  • spacewalk-admin (fixed in 4.2.9-3.6.2)
  • spacewalk-backend (fixed in 4.2.17-4.9.3)
  • spacewalk-certs-tools (fixed in 4.2.13-3.9.2)
  • spacewalk-client-tools (fixed in 4.2.14-4.9.3)
  • spacewalk-java (fixed in 4.2.30-3.14.4)
  • spacewalk-utils (fixed in 4.2.14-3.9.3)
  • spacewalk-web (fixed in 4.2.23-3.9.3)
  • subscription-matcher (fixed in 0.27-6.3.1)
  • supportutils-plugin-susemanager (fixed in 4.2.3-3.3.2)
  • susemanager (fixed in 4.2.25-3.13.1)
  • susemanager-doc-indexes (fixed in 4.2-12.11.3)
  • susemanager-docs-en (fixed in 4.2-12.11.1)
  • susemanager-schema (fixed in 4.2.18-3.9.3)
  • susemanager-sls (fixed in 4.2.18-3.11.1)
  • susemanager-sync-data (fixed in 4.2.9-3.9.1)
  • virtualization-formulas (fixed in 0.6.1-8.3.1)

Timeline and source

Published on 27 October 2021 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2021-10-27
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
cobbler 3.1.2-5.11.1
hub-xmlrpc-api 0.7-3.3.3
inter-server-sync 0.0.5-8.6.3
patterns-suse-manager 4.2-4.3.1
py26-compat-salt 2016.11.10-11.28.9.1
py26-compat-tornado 4.2.1-3.3.1
py27-compat-salt 3000.3-7.7.11.1
spacecmd 4.2.13-4.9.1
spacewalk-admin 4.2.9-3.6.2
spacewalk-backend 4.2.17-4.9.3
spacewalk-certs-tools 4.2.13-3.9.2
spacewalk-client-tools 4.2.14-4.9.3
spacewalk-java 4.2.30-3.14.4
spacewalk-utils 4.2.14-3.9.3
spacewalk-web 4.2.23-3.9.3
subscription-matcher 0.27-6.3.1
supportutils-plugin-susemanager 4.2.3-3.3.2
susemanager 4.2.25-3.13.1
susemanager-doc-indexes 4.2-12.11.3
susemanager-docs-en 4.2-12.11.1
susemanager-schema 4.2.18-3.9.3
susemanager-sls 4.2.18-3.11.1
susemanager-sync-data 4.2.9-3.9.1
virtualization-formulas 0.6.1-8.3.1

References

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2021:3561-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2021:3561-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSE