SUSE-SU-2018:4011-1

    Dashboard / Vulnerabilities / SUSE-SU-2018:4011-1

    SUSE-SU-2018:4011-1

    Published: 7 Dec 2018Last Modified: 4 Feb 2026
    Upstream:

    Summary: Security update for SUSE Manager Server 3.2

    Details: This update fixes the following issues: apache-mybatis: - Install missing LICENSE.txt file (bsc#1114814) cobbler: - Fix service restart after logrotate for cobblerd (bsc#1113747) - Rotate cobbler logs at higher frequency to prevent disk fillup (bsc#1113747) hadoop: - Install missing LICENSE.txt file (bsc#1114814) image-sync-formula: - Handle empty images pillar (bsc#1105359) lucene: - Install missing LICENSE.txt file (bsc#1114814) nekohtml: - Install missing LICENSE.txt file (bsc#1114814) nutch-core: - Install missing LICENSE.txt file (bsc#1114814) - Add conditional requirement for java 1.8 - Use java >= 1.8 - required by tika 0.19.1 to /var/log/nutch (bsc#1107869) - Add new tarball file for v1.0.1 - Bump up version to 1.0.1 and fix paths - Adjustments after upgrade of tika-core to v1.19 picocontainer: - Install missing LICENSE.txt file (bsc#1114814) python-susemanager-retail: - Improve error reporting on duplicate systems - Output partition size as int (bsc#1116517) - Start partition numbers from 1 - Warn on long group names - Improved logging support - Add retail_yaml --only-new option - Print import summary (bsc#1112754) - Add retail_migration tool - Check for duplicate addresses in yaml (bsc#1111497) salt-netapi-client: - Version 0.15.0 See: https://github.com/SUSE/salt-netapi-client/releases/tag/v0.15.0 saltboot-formula: - Send pxe_update by external command to make sure it is finished (bsc#1111387) - Better error message on missing partitioning pillar (bsc#1110625) spacecmd: - Show group id on group_details (bsc#1111542) - State channels handling: Existing commands configchannel_create and configchannel_import were updated while system_scheduleapplyconfigchannels and configchannel_updateinitsls were added. spacewalk-branding: - Automatic cleanup of notification messages after a configurable lifetime - ActivationKey base and child channel in a reactjs component - New messages are added for XMLRPC API for state channels spacewalk-config: - Add permissions for tomcat & apache to check bootstrap ssh file (bsc#1114181) spacewalk-java: - Improve return value and errors thrown for system.createEmptyProfile XMLRPC endpoint - Fix scheduling jobs to prevent forever pending events (bsc#1114991) - Performance improvements for group listings and detail page (bsc#1111810) - Fix wrong counts of systems currency reports when a system belongs to more than one group (bsc#1114362) - Add check if ssh-file permissions are correct (bsc#1114181) - Increase maximum number of threads and open files for taskomatic (bsc#1111966) - When removing cobbler system record, lookup by mac address as well if lookup by id fails(bsc#1110361) - Allow listing empty system profiles via XMLRPC - Automatic cleanup of notification messages after a configurable lifetime - Different methods have been refactored in tomcat/taskomatic for better performance(bsc#1106430) - Do not try cleanup when deleting empty system profiles (bsc#1111247) - Better error handling when a websocket connection is aborted (bsc#1080474) - Change Requires to allow installing with both Tomcat 8 (SLE-12SP3) and 9 (SLE12-SP4) - ActivationKey base and child channel in a reactjs component - Fix typo in messages (bsc#1111249) - Cleanup formula data and assignment when migrating formulas or when removing system - Remove restrictions on SUSE Manager Channel subscriptions (bsc#1105724) - Added shortcut for editing Software Channel - Fix permissions check on formula list api call (bsc#1106626) - Add sp migration dry runs to the daily status report (bsc#1083094) spacewalk-search: - Fix nutch-core path (bsc#1112445) spacewalk-setup: - Increase maximum number of threads and open files for taskomatic (bsc#1111966) spacewalk-utils: - Fix typo at --phases option help spacewalk-web: - Make datetimepicker update displayed time (bsc#1041999) - Show human-readable system cleanup error messages - ActivationKey base and child channel in a reactjs component - Fix typo in messages (bsc#1111249) susemanager: - Add new option --with-parent-channel to mgr-create-bootrap-repo to specify parent channel to use if multiple options are available (bsc#1104487) susemanager-docs_en: - Update text and image files. - Add information about SLE12 SP4 as base OS for Server and Proxy susemanager-frontend-libs: - Fix package version (bsc#1115449) susemanager-schema: - Automatic cleanup of notification messages after a configurable lifetime - Add missing minion-action-chain-cleanup to db init scripts susemanager-sls: - Deploy SSL certificate during onboarding of openSUSE Leap 15.0 (bsc#1112163) susemanager-sync-data: - SUSE OpenStack Cloud 9 enablement (bsc#1113557) - Add SUSE Manager 3.1 and 3.2 to SLES12 SP4 tika-core: - Fix improper XML parsing to prevent DoS attacks (CVE-2018-11761) (bsc#1109235) - Install missing LICENSE.txt file (bsc#1114814) - New upstream version (0.19.1)

    Affected packages

    Package

    Name: spacewalk-web

    Purl: pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Proxy%203.2

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.8.7.11-3.13.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High