SUSE-SU-2021:14833-1
Dashboard / Vulnerabilities / SUSE-SU-2021:14833-1
SUSE-SU-2021:14833-1
Summary: Security update for SUSE Manager Client Tools
Details: This update fixes the following issues: salt: - Exclude the full path of a download URL to prevent injection of malicious code (bsc#1190265) (CVE-2021-21996) spacecmd: - Version 4.2.13-1 * Update translation strings * configchannel_updatefile handles directory properly (bsc#1190512) * Add schedule_archivecompleted to mass archive actions (bsc#1181223) * Remove whoami from the list of unauthenticated commands (bsc#1188977) spacewalk-client-tools: - Version 4.2.14-1 * Update translation strings
References: https://www.suse.com/support/update/announcement/2021/suse-su-202114833-1/, https://bugzilla.suse.com/1181223, https://bugzilla.suse.com/1188977, https://bugzilla.suse.com/1190265, https://bugzilla.suse.com/1190512, https://www.suse.com/security/cve/CVE-2021-21996
Affected packages
Package
Name: salt
Purl: pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLS
Affected ranges
Type: ECOSYSTEM
Events:
