SUSE-SU-2018:3815-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3815-1
SUSE-SU-2018:3815-1
Summary: Security update for salt
Details: This update for salt fixes the following issues: Security issues fixed: - CVE-2018-15750: Fixed directory traversal vulnerability in salt-api (bsc#1113698). - CVE-2018-15751: Fixed remote authentication bypass in salt-api(netapi) that allows to execute arbitrary commands (bsc#1113699). Non-security issues fixed: - Improved handling of LDAP group id. gid is no longer treated as a string, which could have lead to faulty group creations (bsc#1113784). - Fixed async call to process manager (bsc#1110938). - Fixed OS arch detection when RPM is not installed (bsc#1114197).
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183815-1/, https://bugzilla.suse.com/1110938, https://bugzilla.suse.com/1113698, https://bugzilla.suse.com/1113699, https://bugzilla.suse.com/1113784, https://bugzilla.suse.com/1114197, https://www.suse.com/security/cve/CVE-2018-15750, https://www.suse.com/security/cve/CVE-2018-15751
Affected packages
Package
Name: salt
Purl: pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
