🛡️ SUSE-SU-2024:0196-1 — ansible (CVE-2021-3620 +43 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security Beta update for SUSE Manager Client Tools and Salt

This update fixes the following issues:

ansible:

  • Update to version 2.9.27 (jsc#SLE-23631) (jsc#SLE-24133)
  • bsc#1187725 CVE-2021-3620 ansible-connection module discloses sensitive

info in traceback error message (in 2.9.27)

  • bsc#1188061 CVE-2021-3583 Template Injection through yaml multi-line

strings with ansible facts used in template. (in 2.9.23)

  • bsc#1176460 gh#ansible/ansible#72094 ansible module nmcli is broken in

ansible 2.9.13 (in 2.9.15)

  • Update to 2.9.22:
  • CVE-2021-3447 (bsc#1183684) multiple modules expose secured values
  • CVE-2021-20228 (bsc#1181935) basic.py no_log with fallback option
  • CVE-2021-20191 (bsc#1181119) multiple collections exposes secured values
  • CVE-2021-20180 (bsc#1180942) bitbucket_pipeline_variable exposes sensitive values
  • CVE-2021-20178 (bsc#1180816) user data leak in snmp_facts module

dracut-saltboot:

  • Update to version 0.1.1681904360.84ef141
  • Load network configuration even when missing protocol version

(bsc#1210640)

  • Update to verion 0.1.1674034019.a93ff61
  • Install copied wicked config as client.xml (bsc#1205599)
  • Update to version 0.1.1673279145.e7616bd
  • Add failsafe stop file when salt-minion does not stop (bsc#1172110)
  • Copy existing wicked config instead of generating new (bsc#1205599)
  • Update to version 0.1.1665997480.587fa10
  • Add dependencies on xz and gzip to support compressed images
  • Update to version 0.1.1661440542.6cbe0da
  • Use standard susemanager.conf
  • Move image services to dracut-saltboot package
  • Use salt bundle
  • Require e2fsprogs (bsc#1202614)
  • Update to version 0.1.1657643023.0d694ce
  • Update dracut-saltboot dependencies (bsc#1200970)
  • Fix network loading when ipappend is used in pxe config
  • Add new information messages

golang-github-QubitProducts-exporter_exporter:

  • Remove license file from %doc
  • Exclude s390 arch
  • Adapted to build on Enterprise Linux.
  • Fix build for RedHat 7
  • Require Go >= 1.14 also for CentOS
  • Add support for CentOS
  • Replace %{?systemd_requires} with %{?systemd_ordering}

golang-github-boynux-squid_exporter:

  • Exclude s390 architecture (gh#SUSE/spacewalk#19050)
  • Enhanced to build on Enterprise Linux 8.

golang-github-lusitaniae-apache_exporter:

  • Do not strip if SUSE Linux Enterprise 15 SP3
  • Exclude debug for RHEL >= 8
  • Build with Go >= 1.20 when the OS is not RHEL
  • Spec file clean up
  • Fix apparmor profile for SLE 12
  • Do not build with apparmor profile for SLE 12
  • Upgrade to version 1.0.0 (jsc#PED-5405)
  • Improved flag parsing
  • Added support for custom headers
  • Build with Go 1.19
  • Build using promu
  • Add _service file
  • Fix sandboxing options
  • Upgrade to version 0.13.4
  • Fix denial of service vulnerability

(CVE-2022-32149, bsc#1204501)

  • Upgrade to version 0.13.3
  • Fix uncontrolled resource consumption

(CVE-2022-41723, bsc#1208270)

  • Upgrade to version 0.13.1
  • Fix panic caused by missing flagConfig options
  • Upgrade to version 0.13.0
  • Fix authentication bypass vulnarability

(CVE-2022-46146, bsc#1208046)

  • Corrected comment in AppArmor profile
  • Added AppArmor profile
  • Added sandboxing options to systemd service unit
  • Exclude s390 architecture (gh#SUSE/spacewalk#19050)
  • Update to upstream release 0.11.0 (jsc#SLE-24791)
  • Add TLS support
  • Switch to logger, please check --log.level and --log.format

flags

  • Update to version 0.10.1
  • Bugfix: Reset ProxyBalancer metrics on each scrape to

remove stale data

  • Update to version 0.10.0
  • Add Apache Proxy and other metrics
  • Update to version 0.8.0
  • Change commandline flags
  • Add metrics: Apache version, request duration total
  • Adapted to build on Enterprise Linux 8
  • Require building with Go 1.15
  • Add support for RedHat 8

+ Adjust dependencies on spec file

+ Disable dwarf compression in go build

  • Add support for Red Hat
  • Add %license macro for LICENSE file

golang-github-prometheus-prometheus:

  • Update to 2.45.0 (jsc#PED-5406):
  • [FEATURE] API: New limit parameter to limit the number of items

returned by /api/v1/status/tsdb endpoint.

  • [FEATURE] Config: Add limits to global config.
  • [FEATURE] Consul SD: Added support for path_prefix.
  • [FEATURE] Native histograms: Add option to scrape both classic

and native histograms.

  • [FEATURE] Native histograms: Added support for two more

arithmetic operators avg_over_time and sum_over_time.

  • [FEATURE] Promtool: When providing the block id, only one block

will be loaded and analyzed.

  • [FEATURE] Remote-write: New Azure ad configuration to support

remote writing directly to Azure Monitor workspace.

  • [FEATURE] TSDB: Samples per chunk are now configurable with

flag storage.tsdb.samples-per-chunk. By default set to its

former value 120.

  • [ENHANCEMENT] Native histograms: bucket size can now be limited

to avoid scrape fails.

  • [ENHANCEMENT] TSDB: Dropped series ar

Affected software

SUSE-SU-2024:0196-1 is recorded against 19 packages.

  • ansible (fixed in 2.9.27-159000.3.9.1)
  • dracut-saltboot (fixed in 0.1.1681904360.84ef141-159000.3.30.1)
  • golang-github-boynux-squid-exporter (fixed in 1.6-159000.4.9.1)
  • golang-github-lusitaniae-apache-exporter (fixed in 1.0.0-159000.4.12.1)
  • golang-github-prometheus-prometheus (fixed in 2.45.0-159000.6.33.1)
  • golang-github-qubitproducts-exporter-exporter (fixed in 0.4.0-159000.4.6.1)
  • grafana (fixed in 9.5.8-159000.4.24.1)
  • mgr-push (fixed in 5.0.1-159000.4.21.1)
  • prometheus-blackbox-exporter (fixed in 0.24.0-159000.3.6.1)
  • prometheus-postgres-exporter (fixed in 0.10.1-159000.3.6.1)
  • python-hwdata (fixed in 2.3.5-159000.5.13.1)
  • python-pyvmomi (fixed in 6.7.3-159000.3.6.1)
  • rhnlib (fixed in 5.0.1-159000.6.30.1)
  • spacecmd (fixed in 5.0.1-159000.6.42.1)
  • spacewalk-client-tools (fixed in 5.0.1-159000.6.48.1)
  • supportutils-plugin-salt (fixed in 1.2.2-159000.5.9.1)
  • supportutils-plugin-susemanager-client (fixed in 5.0.1-159000.6.15.1)
  • uyuni-common-libs (fixed in 5.0.1-159000.3.33.1)
  • uyuni-proxy-systemd-services (fixed in 5.0.1-159000.3.9.1)

Timeline and source

Published on 23 January 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-01-23
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
ansible 2.9.27-159000.3.9.1
dracut-saltboot 0.1.1681904360.84ef141-159000.3.30.1
golang-github-boynux-squid-exporter 1.6-159000.4.9.1
golang-github-lusitaniae-apache-exporter 1.0.0-159000.4.12.1
golang-github-prometheus-prometheus 2.45.0-159000.6.33.1
golang-github-qubitproducts-exporter-exporter 0.4.0-159000.4.6.1
grafana 9.5.8-159000.4.24.1
mgr-push 5.0.1-159000.4.21.1
prometheus-blackbox-exporter 0.24.0-159000.3.6.1
prometheus-postgres-exporter 0.10.1-159000.3.6.1
python-hwdata 2.3.5-159000.5.13.1
python-pyvmomi 6.7.3-159000.3.6.1
rhnlib 5.0.1-159000.6.30.1
spacecmd 5.0.1-159000.6.42.1
spacewalk-client-tools 5.0.1-159000.6.48.1
supportutils-plugin-salt 1.2.2-159000.5.9.1
supportutils-plugin-susemanager-client 5.0.1-159000.6.15.1
uyuni-common-libs 5.0.1-159000.3.33.1
uyuni-proxy-systemd-services 5.0.1-159000.3.9.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2024:0196-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:0196-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2024