SUSE-SU-2017:2453-1
Dashboard / Vulnerabilities / SUSE-SU-2017:2453-1
SUSE-SU-2017:2453-1
Summary: Security update for SUSE Manager Server 3.0
Details: This update for the SUSE Manager Server 3.0 provides several fixes and improvements. The following security issue has been fixed: spacewalk-java: - CVE-2017-7538: Do not allow HTML code injection via Cross Site Scripting (XSS) in the Organization Name. (bsc#1048968) Additionally, the following non-security issues have been fixed: salt-netapi-client: - Fix date format for Schedule. - Fix sending kwarg in payload in RunnerCall. - Better error handling in Runner and Wheel calls. - Increase the default SOCKET_TIMEOUT to 20 seconds smdba: - Do not set default_statistics_target. (bsc#1022286) - Support postgresql96. (bsc#1045152) - Prevent use of /var/lib/pgsql/data. (bsc#1024058) - Remove copyright message every time shown. - On systemd-enabled systems use it for start/stop PostgreSQL. (bsc#1024058) spacewalk-backend: - Increase rpclib timeout to 10 minutes. (bsc#1026930) - Adapt for the new gpgcheck flag for the channels. spacewalk-branding: - Fix overlapping text narrow window. (bsc#1009118) spacewalk-config: - Resolve comps.xml file for repositories. (bsc#1048528) spacewalk-java: - Delete and create new ServerNetAddress if it already exists on Hardware refresh. (bsc#1054225) - Fix enter key submit on ListTag filter input. (bsc#1048762) - Create VirtpollerData object with JSON content instead null. (bsc#1049170) - Prevent malformed XML if 'arch' is set to NULL. (bsc#1045575) - Resolve comps.xml file for repositories. (bsc#1048528) - Don't add default channel if AK is not valid. (bsc#1047656) - Add 'Enable GPG check' function for channels. - Regenerate pillar for the minions using the channel being modified. - Remove executable bit from service files. (bsc#1051518) - Fix wrong openscap xid. (bsc#1030898) - Fix overlapping text narrow window. (bsc#1009118) - Fix broken link. (bsc#1033999) - Fix alignment on the org details. (bsc#1017513) - Update channels.xml with OpenStack Cloud Continuous Delivery 6. (bsc#1039458) - Handle possible wrong UUIDs on SLE 11 minions. (bsc#1046218) - Allow blank key generation. (bsc#1032350) spacewalk-search: - Remove executable bit from service files. (bsc#1051518) spacewalk-setup-jabberd: - Change default backend for jabberd to sqlite. (bsc#1047155) spacewalk-web: - Fix enter key submit on ListTag filter input. (bsc#1048762) susemanager: - Do not use checkpoint_segments parameter during migrations. - Enable migration from postgresql94 to postgresql96. - Create bootstrap repository for SUSE Linux Enterprise Server for SAP 11 SP1. (bsc#1049471) - Adjust the bootstrap repository with SUSE Linux Enterprise 12 SP3 repositories. susemanager-docs_en: - Update text and image files. susemanager-schema: - Adapt for the new gpgcheck flag for the channels. susemanager-sync-data: - Add SUSE Manager Proxy 3.0 channels for SUSE Linux Enterprise Server 12 SP3. (bsc#1053850) - Support SUSE Enterprise Storage 5 and SUSE Linux Enterprise Server 12 SP3 for SAP Applications on ppc64le. (bsc#1028098) - Update channels.xml with OpenStack Cloud Continuous Delivery 6. (bsc#1039458) - Add SUSE Linux Enterprise 12 SP3 related products. (bsc#1037609) virtual-host-gatherer: - Implement kubernetes gatherer module. How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: spacewalk-service stop 3. Apply the patch using either zypper patch or YaST Online Update. 4. Upgrade the database schema: spacewalk-schema-upgrade 5. Start the Spacewalk service: spacewalk-service start
References: https://www.suse.com/support/update/announcement/2017/suse-su-20172453-1/, https://bugzilla.suse.com/1009118, https://bugzilla.suse.com/1017513, https://bugzilla.suse.com/1022286, https://bugzilla.suse.com/1024058, https://bugzilla.suse.com/1026930, https://bugzilla.suse.com/1028098, https://bugzilla.suse.com/1030898, https://bugzilla.suse.com/1032350, https://bugzilla.suse.com/1033999, https://bugzilla.suse.com/1037609, https://bugzilla.suse.com/1039458, https://bugzilla.suse.com/1045152, https://bugzilla.suse.com/1045575, https://bugzilla.suse.com/1046218, https://bugzilla.suse.com/1047155, https://bugzilla.suse.com/1047656, https://bugzilla.suse.com/1048528, https://bugzilla.suse.com/1048762, https://bugzilla.suse.com/1048968, https://bugzilla.suse.com/1049170, https://bugzilla.suse.com/1049471, https://bugzilla.suse.com/1051518, https://bugzilla.suse.com/1053850, https://bugzilla.suse.com/1054225, https://www.suse.com/security/cve/CVE-2017-7538
Affected packages
Package
Name: salt-netapi-client
Purl: pkg:rpm/suse/salt-netapi-client&distro=SUSE%20Manager%20Server%203.0
Affected ranges
Type: ECOSYSTEM
Events:
