SUSE-SU-2022:2568-1

    Dashboard / Vulnerabilities / SUSE-SU-2022:2568-1

    SUSE-SU-2022:2568-1

    Published: 27 Jul 2022Last Modified: 4 Feb 2026
    Upstream:

    Summary: Security update for SUSE Manager Server 4.2

    Details: This update fixes the following issues: apache-commons-csv: - Fix the URL for the package - Declare the LICENSE file as license and not doc apache-commons-math3: - Fix the URL for the package - Declare the LICENSE file as license and not doc drools: - Declare the LICENSE file as license and not doc jakarta-commons-validator: - Declare the LICENSE file as license and not doc jose4j: - Declare the LICENSE file as license and not doc kie-api: - Declare the LICENSE file as license and not doc mvel2: - Declare the LICENSE file as license and not doc optaplanner: - Declare the LICENSE file as license and not doc py27-compat-salt: - Remove redundant overrides causing confusing DEBUG logging (bsc#1189501) python-susemanager-retail: - Update to version 1.0.1653987003.92d4870 * Fix messages and logging in retail_create_delta (bsc#1199727) smdba: - Declare the LICENSE file as license and not doc - Make EL egginfo removal more generic spacecmd: - Version 4.2.18-1 * on full system update call schedulePackageUpdate API (bsc#1197507) spacewalk-admin: - Version 4.2.11-1 * clarify schema upgrade check message (bsc#1198999) spacewalk-backend: - Version 4.2.23-1 * Fix traceback on calling spacewalk-repo-sync --show-packages (bsc#1193238) * Fix virt_notify SQL syntax error (bsc#1199528) * store create-bootstrap logs in spacewalk-debug spacewalk-branding: - Version 4.2.14-1 * Stylesheets and relevant assets are now provided by spacewalk-web spacewalk-certs-tools: - Version 4.2.17-1 * use RES bootstrap repo as a fallback for Red Hat downstream OS (bsc#1200087) spacewalk-client-tools: - Version 4.2.19-1 * Update translation strings spacewalk-java: - version 4.2.40-1 * Fix conflict when system is assigned to multiple instances of the same formula (bsc#1194394) - Version 4.2.39-1 * Keep the websocket connections alive with ping/pong frames (bsc#1199874) * Fix missing remote command history events for big output (bsc#1199656) * Improve CLM channel cloning performance (bsc#1199523) * fix api log message references the wrong user (bsc#1179962) * Show patch as installed in CVE Audit even if successor patch affects additional packages (bsc#1199646) * fix download of packages with caret sign in the version due to missing url decode * Prefer the Salt Bundle with Cobbler snippets configuration (minion_script and redhat_register_using_salt) (bsc#1198646) * During re-activation, recalculate grains if contact method has been changed (bsc#1199677) * Hide authentication data in PAYG UI (bsc#1199679) * autoinstallation: missing whitespace after install URL (bsc#1199888) * Improved handling of error messages during bootstrapping * skip forwarding data to scc if no credentials are available * Change system details lock tab name to lock/unlock (bsc#1193032) * Added a notification to inform the administrators about the product end-of-life * Set profile tag has no-mandatory in XCCDF result (bsc#1194262) * provisioning thought proxy should use proxy for self_update (bsc#1199036) * Allow removing duplicated packages names in the same Salt action (bsc#1198686) * fix NoSuchElementException when pkg install date is missing * Improve API documentation * Fix outdated documentation and release notes links * Fix error message in Kubernetes VHM creation dialog * Add createAppStreamFilters() XMLRPC function * Correct concurrency error on payg taskomatic task for updating certificates (#17783) * Fix ACL rules for config diff download for SLS files (bsc#1198914) * fix package selection for ubuntu errata install (bsc#1199049) * fix invalid link to action schedule * add schedulePackageUpdate() XMLRPC function (bsc#1197507) * update server needed cache after adding Ubuntu Errata (bsc#1196977) * check if file exists before sending it to xsendfile (bsc#1198191) * Display usertime instead of server time for clm issue date filter (bsc#1198429) * Redesign the auto errata task to schedule combined actions (bsc#1197429) * Fix send login(s) and send password actions to avoid user enumeration (bsc#1199629) (CVE-2022-31248) spacewalk-search: - Version 4.2.7-1 * Update development configuration file spacewalk-setup: - Version 4.2.11-1 * spacewalk-setup-cobbler assumes /etc/apache2/conf.d now as a default instead of /etc/httpd/conf.d (bsc#1198356) spacewalk-utils: - Version 4.2.17-1 * spacewalk-hostname-rename now correctly replaces the hostname for the mgr-sync configuration file (bsc#1198356) * spacewalk-hostname-rename now utilizes the '--apache2-conf-dir' flag for spacewalk-setup-cobbler (bsc#1198356) spacewalk-web: - Version 4.2.28-1 * Stylesheets and relevant assets are now provided by spacewalk-web * Remove nodejs-packaging as a build requirement * Hide authentication data in PAYG UI (bsc#1199679) * Improved handling of error messages during bootstrapping * Added support for end of life notifications * Improved test integration for dropdowns * Upgrade moment to 2.29.2 * Fix outdated documentation and release notes links * Fix mimetype in kubeconfig validation request (bsc#1199019) subscription-matcher: - Declare the LICENSE file as license and not doc susemanager: - version 4.2.35-1 * Add missing python3-gnupg to Debian10 bootstrap repo (bsc#1201842) - Version 4.2.34-1 * mgr-sync: Raise a proper exception when duplicated lines exist in a config file (bsc#1182742) * add SLED 12 SP3 bootstrap repo definition (bsc#1199438) - Version 4.2.33-1 * Fix issue with bootstrap repo definitions for RHEL/RES8 variants (bsc#1200863) susemanager-doc-indexes: - Fixed the 'fast' switch ('-f') of the database migration script in the Installation and Upgrade Guides - Updated the Virtualization chapter in the Client Configuration Guide - Added information about registering RHEL clients on Azure in the Import Entitlements and Certificates section of the Client Configuration Guide (bsc#1198944) - In the Client Configuration Guide, package locking is now supported for Ubuntu and Debian - Fixed VisibleIf documentation in the Formula section of the Salt Guide - Added note about importing CA certifcates in the Installation and Upgrade Guide (bsc#1198358) - Documented how to define monitored targets using the file-based service discovery provided in the Prometheus formula of the Salt Guide - Add note about OpenSCAP security profile support in OpenSCAP section of the Administration Guide - Fixed spacewalk-remove-channel command in Delete Channels section of the Administration Guide (bsc#1199596) - Large deployments guide now includes a mention of the proxy (bsc#1199577) - Enhanced the Product Migration chapter of the Client Configuration Guide with a SUSE Linux Enterprise example susemanager-docs_en: - Fixed the 'fast' switch ('-f') of the database migration script in the Installation and Upgrade Guides - Updated the Virtualization chapter in the Client Configuration Guide - Added information about registering RHEL clients on Azure in the Import Entitlements and Certificates section of the Client Configuration Guide (bsc#1198944) - In the Client Configuration Guide, package locking is now supported for Ubuntu and Debian - Fixed VisibleIf documentation in the Formula section of the Salt Guide - Added note about importing CA certifcates in the Installation and Upgrade Guide (bsc#1198358) - Documented how to define monitored targets using the file-based service discovery provided in the Prometheus formula of the Salt Guide - Add note about OpenSCAP security profile support in OpenSCAP section of the Administration Guide - Fixed spacewalk-remove-channel command in Delete Channels section of the Administration Guide (bsc#1199596) - Large deployments guide now includes a mention of the proxy (bsc#1199577) - Enhanced the Product Migration chapter of the Client Configuration Guide with a SUSE Linux Enterprise example susemanager-schema: - Version 4.2.23-1 * Add schema directory for susemanager-schema-4.2.22 susemanager-sls: - version 4.2.26-1 * Fix issue bootstrap issue with Debian 9 because missing python3-contextvars (bsc#1201782) - Version 4.2.25-1 * use RES bootstrap repo as a fallback for Red Hat downstream OS (bsc#1200087) * Add support to packages.pkgremove to deal with duplicated pkg names (bsc#1198686) * do not install products and gpg keys when performing distupgrade dry-run (bsc#1199466) * Fix deprecated warning when getting pillar data (bsc#1192850) * remove unknown repository flags on EL * add packages.pkgupdate state (bsc#1197507) - Version 4.2.24-1 * Manage the correct minion config file when venv-salt-minion is installed (bsc#1200703) * Fix bootstrapping for Ubuntu 18.04 with classic Salt package (bsc#1200707) susemanager-sync-data: - Version 4.2.13-1 * change release status of Debian 11 to released virtual-host-gatherer: - Declare the LICENSE file as license and not doc woodstox: - Declare the LICENSE file as license and not doc xmlpull-api: - Declare the LICENSE file as license and not doc How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: `spacewalk-service stop` 3. Apply the patch using either zypper patch or YaST Online Update. 4. Start the Spacewalk service: `spacewalk-service start`

    References: https://www.suse.com/support/update/announcement/2022/suse-su-20222568-1/, https://bugzilla.suse.com/1179962, https://bugzilla.suse.com/1182742, https://bugzilla.suse.com/1189501, https://bugzilla.suse.com/1192850, https://bugzilla.suse.com/1193032, https://bugzilla.suse.com/1193238, https://bugzilla.suse.com/1194262, https://bugzilla.suse.com/1194394, https://bugzilla.suse.com/1196977, https://bugzilla.suse.com/1197429, https://bugzilla.suse.com/1197507, https://bugzilla.suse.com/1198191, https://bugzilla.suse.com/1198356, https://bugzilla.suse.com/1198358, https://bugzilla.suse.com/1198429, https://bugzilla.suse.com/1198646, https://bugzilla.suse.com/1198686, https://bugzilla.suse.com/1198914, https://bugzilla.suse.com/1198944, https://bugzilla.suse.com/1198999, https://bugzilla.suse.com/1199019, https://bugzilla.suse.com/1199036, https://bugzilla.suse.com/1199049, https://bugzilla.suse.com/1199438, https://bugzilla.suse.com/1199466, https://bugzilla.suse.com/1199523, https://bugzilla.suse.com/1199528, https://bugzilla.suse.com/1199577, https://bugzilla.suse.com/1199596, https://bugzilla.suse.com/1199629, https://bugzilla.suse.com/1199646, https://bugzilla.suse.com/1199656, https://bugzilla.suse.com/1199677, https://bugzilla.suse.com/1199679, https://bugzilla.suse.com/1199727, https://bugzilla.suse.com/1199874, https://bugzilla.suse.com/1199888, https://bugzilla.suse.com/1200087, https://bugzilla.suse.com/1200703, https://bugzilla.suse.com/1200707, https://bugzilla.suse.com/1200863, https://bugzilla.suse.com/1201782, https://bugzilla.suse.com/1201842, https://www.suse.com/security/cve/CVE-2022-31248

    Affected packages

    Package

    Name: apache-commons-csv

    Purl: pkg:rpm/suse/apache-commons-csv&distro=SUSE%20Manager%20Server%20Module%204.2

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.2-150300.3.3.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2022:2568-1 | CVE-DB