SUSE-SU-2022:1536-1

    Dashboard / Vulnerabilities / SUSE-SU-2022:1536-1

    SUSE-SU-2022:1536-1

    Published: 4 May 2022Last Modified: 4 Feb 2026

    Summary: Security Beta update for SUSE Manager Salt Bundle

    Details: This update fixes the following issues: venv-salt-minion: - Fix the regression caused by the patch removing strict requirement for OpenSSL 1.1.1 leading to read/write issues with ssl module for SLE 15, SLE 12, CentOS 7, Debian 9 (bsc#1198556) - Fixes for Python 3.10 - Fix salt-ssh opts poisoning (bsc#1197637) - Fix multiple security issues (bsc#1197417) * CVE-2022-22935: Sign authentication replies to prevent MiTM * CVE-2022-22934: Sign pillar data to prevent MiTM attacks. * CVE-2022-22936: Prevent job and fileserver replays. * CVE-2022-22941: Fixed targeting bug, especially visible when using syndic and user auth. - Salt version bump to 3004 - Python version bump to 3.10.2 - CVE-2022-24302: unauthorized information disclosure for python-paramiko. - CVE-2021-28957: XSS due to missing input sanitization in python-lxml. - CVE-2018-19787: XSS attacks due to missing URLs sanitization in python-lxml. - Security Fix: (bsc#1196249, bsc#1196877, CVE-2022-0778) * Allow CRYPTO_THREADID_set_callback to be called with NULL parameter * Infinite loop in BN_mod_sqrt() reachable when parsing certificates

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2022:1536-1 | CVE-DB