SUSE-RU-2018:4018-1
Dashboard / Vulnerabilities / SUSE-RU-2018:4018-1
SUSE-RU-2018:4018-1
Summary: Security update for SUSE Manager Server 3.2
Details: This update fixes the following issues: apache-mybatis: - Install missing LICENSE.txt file (bsc#1114814) cobbler: - Fix service restart after logrotate for cobblerd (bsc#1113747) - Rotate cobbler logs at higher frequency to prevent disk fillup (bsc#1113747) hadoop: - Install missing LICENSE.txt file (bsc#1114814) image-sync-formula: - Handle empty images pillar (bsc#1105359) lucene: - Install missing LICENSE.txt file (bsc#1114814) nekohtml: - Install missing LICENSE.txt file (bsc#1114814) nutch-core: - Install missing LICENSE.txt file (bsc#1114814) - Add conditional requirement for java 1.8 - Use java >= 1.8 - required by tika 0.19.1 to /var/log/nutch (bsc#1107869) - Add new tarball file for v1.0.1 - Bump up version to 1.0.1 and fix paths - Adjustments after upgrade of tika-core to v1.19 picocontainer: - Install missing LICENSE.txt file (bsc#1114814) python-susemanager-retail: - Improve error reporting on duplicate systems - Output partition size as int (bsc#1116517) - Start partition numbers from 1 - Warn on long group names - Improved logging support - Add retail_yaml --only-new option - Print import summary (bsc#1112754) - Add retail_migration tool - Check for duplicate addresses in yaml (bsc#1111497) salt-netapi-client: - Version 0.15.0 See: https://github.com/SUSE/salt-netapi-client/releases/tag/v0.15.0 saltboot-formula: - Send pxe_update by external command to make sure it is finished (bsc#1111387) - Better error message on missing partitioning pillar (bsc#1110625) spacecmd: - Show group id on group_details (bsc#1111542) - State channels handling: Existing commands configchannel_create and configchannel_import were updated while system_scheduleapplyconfigchannels and configchannel_updateinitsls were added. spacewalk-branding: - Automatic cleanup of notification messages after a configurable lifetime - ActivationKey base and child channel in a reactjs component - New messages are added for XMLRPC API for state channels spacewalk-config: - Add permissions for tomcat & apache to check bootstrap ssh file (bsc#1114181) spacewalk-java: - Improve return value and errors thrown for system.createEmptyProfile XMLRPC endpoint - Fix scheduling jobs to prevent forever pending events (bsc#1114991) - Performance improvements for group listings and detail page (bsc#1111810) - Fix wrong counts of systems currency reports when a system belongs to more than one group (bsc#1114362) - Add check if ssh-file permissions are correct (bsc#1114181) - Increase maximum number of threads and open files for taskomatic (bsc#1111966) - When removing cobbler system record, lookup by mac address as well if lookup by id fails(bsc#1110361) - Allow listing empty system profiles via XMLRPC - Automatic cleanup of notification messages after a configurable lifetime - Different methods have been refactored in tomcat/taskomatic for better performance(bsc#1106430) - Do not try cleanup when deleting empty system profiles (bsc#1111247) - Better error handling when a websocket connection is aborted (bsc#1080474) - Change Requires to allow installing with both Tomcat 8 (SLE-12SP3) and 9 (SLE12-SP4) - ActivationKey base and child channel in a reactjs component - Fix typo in messages (bsc#1111249) - Cleanup formula data and assignment when migrating formulas or when removing system - Remove restrictions on SUSE Manager Channel subscriptions (bsc#1105724) - Added shortcut for editing Software Channel - Fix permissions check on formula list api call (bsc#1106626) - Add sp migration dry runs to the daily status report (bsc#1083094) spacewalk-search: - Fix nutch-core path (bsc#1112445) spacewalk-setup: - Increase maximum number of threads and open files for taskomatic (bsc#1111966) spacewalk-utils: - Fix typo at --phases option help spacewalk-web: - Make datetimepicker update displayed time (bsc#1041999) - Show human-readable system cleanup error messages - ActivationKey base and child channel in a reactjs component - Fix typo in messages (bsc#1111249) susemanager: - Add new option --with-parent-channel to mgr-create-bootrap-repo to specify parent channel to use if multiple options are available (bsc#1104487) susemanager-docs_en: - Update text and image files. - Add information about SLE12 SP4 as base OS for Server and Proxy susemanager-frontend-libs: - Fix package version (bsc#1115449) susemanager-schema: - Automatic cleanup of notification messages after a configurable lifetime - Add missing minion-action-chain-cleanup to db init scripts susemanager-sls: - Deploy SSL certificate during onboarding of openSUSE Leap 15.0 (bsc#1112163) susemanager-sync-data: - SUSE OpenStack Cloud 9 enablement (bsc#1113557) - Add SUSE Manager 3.1 and 3.2 to SLES12 SP4 tika-core: - Fix improper XML parsing to prevent DoS attacks (CVE-2018-11761) (bsc#1109235) - Install missing LICENSE.txt file (bsc#1114814) - New upstream version (0.19.1)
References: https://www.suse.com/support/update/announcement//suse-ru-20184018-1/, https://bugzilla.suse.com/1041999, https://bugzilla.suse.com/1080474, https://bugzilla.suse.com/1083094, https://bugzilla.suse.com/1104487, https://bugzilla.suse.com/1105359, https://bugzilla.suse.com/1105724, https://bugzilla.suse.com/1106430, https://bugzilla.suse.com/1106626, https://bugzilla.suse.com/1107869, https://bugzilla.suse.com/1109235, https://bugzilla.suse.com/1110361, https://bugzilla.suse.com/1110625, https://bugzilla.suse.com/1111247, https://bugzilla.suse.com/1111249, https://bugzilla.suse.com/1111387, https://bugzilla.suse.com/1111497, https://bugzilla.suse.com/1111542, https://bugzilla.suse.com/1111810, https://bugzilla.suse.com/1111966, https://bugzilla.suse.com/1112163, https://bugzilla.suse.com/1112445, https://bugzilla.suse.com/1112754, https://bugzilla.suse.com/1113557, https://bugzilla.suse.com/1113747, https://bugzilla.suse.com/1114181, https://bugzilla.suse.com/1114362, https://bugzilla.suse.com/1114814, https://bugzilla.suse.com/1114991, https://bugzilla.suse.com/1115449, https://bugzilla.suse.com/1116517, https://www.suse.com/security/cve/CVE-2018-11761
Affected packages
Package
Name: spacewalk-web
Purl: pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Proxy%203.2
Affected ranges
Type: ECOSYSTEM
Events:
