SUSE-SU-2022:0509-1
Dashboard / Vulnerabilities / SUSE-SU-2022:0509-1
SUSE-SU-2022:0509-1
Summary: Security update for cobbler
Details: This update for cobbler fixes the following issues: - CVE-2021-45083: Fixed unsafe permissions on sensitive files (bsc#1193671). - CVE-2021-45082: Fixed incomplete template sanitation (bsc#1193678). The following non-security bugs were fixed: - Fix issues with installation module logging and validation (bsc#1195918) - Move configuration files ownership to apache (bsc#1195906) - Remove hardcoded test credentials (bsc#1193673) - Prevent log pollution (bsc#1193675) - Missing sanity check on MongoDB configuration file (bsc#1193676)
References: https://www.suse.com/support/update/announcement/2022/suse-su-20220509-1/, https://bugzilla.suse.com/1193671, https://bugzilla.suse.com/1193673, https://bugzilla.suse.com/1193675, https://bugzilla.suse.com/1193676, https://bugzilla.suse.com/1193678, https://bugzilla.suse.com/1195906, https://bugzilla.suse.com/1195918, https://www.suse.com/security/cve/CVE-2021-45082, https://www.suse.com/security/cve/CVE-2021-45083
Affected packages
Package
Name: cobbler
Purl: pkg:rpm/suse/cobbler&distro=SUSE%20Manager%20Server%20Module%204.2
Affected ranges
Type: ECOSYSTEM
Events:
